162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * Cryptographic API. 462306a36Sopenharmony_ci * 562306a36Sopenharmony_ci * Support for ATMEL AES HW acceleration. 662306a36Sopenharmony_ci * 762306a36Sopenharmony_ci * Copyright (c) 2012 Eukréa Electromatique - ATMEL 862306a36Sopenharmony_ci * Author: Nicolas Royer <nicolas@eukrea.com> 962306a36Sopenharmony_ci * 1062306a36Sopenharmony_ci * Some ideas are from omap-aes.c driver. 1162306a36Sopenharmony_ci */ 1262306a36Sopenharmony_ci 1362306a36Sopenharmony_ci 1462306a36Sopenharmony_ci#include <linux/kernel.h> 1562306a36Sopenharmony_ci#include <linux/module.h> 1662306a36Sopenharmony_ci#include <linux/slab.h> 1762306a36Sopenharmony_ci#include <linux/err.h> 1862306a36Sopenharmony_ci#include <linux/clk.h> 1962306a36Sopenharmony_ci#include <linux/io.h> 2062306a36Sopenharmony_ci#include <linux/hw_random.h> 2162306a36Sopenharmony_ci#include <linux/platform_device.h> 2262306a36Sopenharmony_ci 2362306a36Sopenharmony_ci#include <linux/device.h> 2462306a36Sopenharmony_ci#include <linux/dmaengine.h> 2562306a36Sopenharmony_ci#include <linux/init.h> 2662306a36Sopenharmony_ci#include <linux/errno.h> 2762306a36Sopenharmony_ci#include <linux/interrupt.h> 2862306a36Sopenharmony_ci#include <linux/irq.h> 2962306a36Sopenharmony_ci#include <linux/scatterlist.h> 3062306a36Sopenharmony_ci#include <linux/dma-mapping.h> 3162306a36Sopenharmony_ci#include <linux/mod_devicetable.h> 3262306a36Sopenharmony_ci#include <linux/delay.h> 3362306a36Sopenharmony_ci#include <linux/crypto.h> 3462306a36Sopenharmony_ci#include <crypto/scatterwalk.h> 3562306a36Sopenharmony_ci#include <crypto/algapi.h> 3662306a36Sopenharmony_ci#include <crypto/aes.h> 3762306a36Sopenharmony_ci#include <crypto/gcm.h> 3862306a36Sopenharmony_ci#include <crypto/xts.h> 3962306a36Sopenharmony_ci#include <crypto/internal/aead.h> 4062306a36Sopenharmony_ci#include <crypto/internal/skcipher.h> 4162306a36Sopenharmony_ci#include "atmel-aes-regs.h" 4262306a36Sopenharmony_ci#include "atmel-authenc.h" 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_ci#define ATMEL_AES_PRIORITY 300 4562306a36Sopenharmony_ci 4662306a36Sopenharmony_ci#define ATMEL_AES_BUFFER_ORDER 2 4762306a36Sopenharmony_ci#define ATMEL_AES_BUFFER_SIZE (PAGE_SIZE << ATMEL_AES_BUFFER_ORDER) 4862306a36Sopenharmony_ci 4962306a36Sopenharmony_ci#define CFB8_BLOCK_SIZE 1 5062306a36Sopenharmony_ci#define CFB16_BLOCK_SIZE 2 5162306a36Sopenharmony_ci#define CFB32_BLOCK_SIZE 4 5262306a36Sopenharmony_ci#define CFB64_BLOCK_SIZE 8 5362306a36Sopenharmony_ci 5462306a36Sopenharmony_ci#define SIZE_IN_WORDS(x) ((x) >> 2) 5562306a36Sopenharmony_ci 5662306a36Sopenharmony_ci/* AES flags */ 5762306a36Sopenharmony_ci/* Reserve bits [18:16] [14:12] [1:0] for mode (same as for AES_MR) */ 5862306a36Sopenharmony_ci#define AES_FLAGS_ENCRYPT AES_MR_CYPHER_ENC 5962306a36Sopenharmony_ci#define AES_FLAGS_GTAGEN AES_MR_GTAGEN 6062306a36Sopenharmony_ci#define AES_FLAGS_OPMODE_MASK (AES_MR_OPMOD_MASK | AES_MR_CFBS_MASK) 6162306a36Sopenharmony_ci#define AES_FLAGS_ECB AES_MR_OPMOD_ECB 6262306a36Sopenharmony_ci#define AES_FLAGS_CBC AES_MR_OPMOD_CBC 6362306a36Sopenharmony_ci#define AES_FLAGS_OFB AES_MR_OPMOD_OFB 6462306a36Sopenharmony_ci#define AES_FLAGS_CFB128 (AES_MR_OPMOD_CFB | AES_MR_CFBS_128b) 6562306a36Sopenharmony_ci#define AES_FLAGS_CFB64 (AES_MR_OPMOD_CFB | AES_MR_CFBS_64b) 6662306a36Sopenharmony_ci#define AES_FLAGS_CFB32 (AES_MR_OPMOD_CFB | AES_MR_CFBS_32b) 6762306a36Sopenharmony_ci#define AES_FLAGS_CFB16 (AES_MR_OPMOD_CFB | AES_MR_CFBS_16b) 6862306a36Sopenharmony_ci#define AES_FLAGS_CFB8 (AES_MR_OPMOD_CFB | AES_MR_CFBS_8b) 6962306a36Sopenharmony_ci#define AES_FLAGS_CTR AES_MR_OPMOD_CTR 7062306a36Sopenharmony_ci#define AES_FLAGS_GCM AES_MR_OPMOD_GCM 7162306a36Sopenharmony_ci#define AES_FLAGS_XTS AES_MR_OPMOD_XTS 7262306a36Sopenharmony_ci 7362306a36Sopenharmony_ci#define AES_FLAGS_MODE_MASK (AES_FLAGS_OPMODE_MASK | \ 7462306a36Sopenharmony_ci AES_FLAGS_ENCRYPT | \ 7562306a36Sopenharmony_ci AES_FLAGS_GTAGEN) 7662306a36Sopenharmony_ci 7762306a36Sopenharmony_ci#define AES_FLAGS_BUSY BIT(3) 7862306a36Sopenharmony_ci#define AES_FLAGS_DUMP_REG BIT(4) 7962306a36Sopenharmony_ci#define AES_FLAGS_OWN_SHA BIT(5) 8062306a36Sopenharmony_ci 8162306a36Sopenharmony_ci#define AES_FLAGS_PERSISTENT AES_FLAGS_BUSY 8262306a36Sopenharmony_ci 8362306a36Sopenharmony_ci#define ATMEL_AES_QUEUE_LENGTH 50 8462306a36Sopenharmony_ci 8562306a36Sopenharmony_ci#define ATMEL_AES_DMA_THRESHOLD 256 8662306a36Sopenharmony_ci 8762306a36Sopenharmony_ci 8862306a36Sopenharmony_cistruct atmel_aes_caps { 8962306a36Sopenharmony_ci bool has_dualbuff; 9062306a36Sopenharmony_ci bool has_cfb64; 9162306a36Sopenharmony_ci bool has_gcm; 9262306a36Sopenharmony_ci bool has_xts; 9362306a36Sopenharmony_ci bool has_authenc; 9462306a36Sopenharmony_ci u32 max_burst_size; 9562306a36Sopenharmony_ci}; 9662306a36Sopenharmony_ci 9762306a36Sopenharmony_cistruct atmel_aes_dev; 9862306a36Sopenharmony_ci 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_citypedef int (*atmel_aes_fn_t)(struct atmel_aes_dev *); 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci 10362306a36Sopenharmony_cistruct atmel_aes_base_ctx { 10462306a36Sopenharmony_ci struct atmel_aes_dev *dd; 10562306a36Sopenharmony_ci atmel_aes_fn_t start; 10662306a36Sopenharmony_ci int keylen; 10762306a36Sopenharmony_ci u32 key[AES_KEYSIZE_256 / sizeof(u32)]; 10862306a36Sopenharmony_ci u16 block_size; 10962306a36Sopenharmony_ci bool is_aead; 11062306a36Sopenharmony_ci}; 11162306a36Sopenharmony_ci 11262306a36Sopenharmony_cistruct atmel_aes_ctx { 11362306a36Sopenharmony_ci struct atmel_aes_base_ctx base; 11462306a36Sopenharmony_ci}; 11562306a36Sopenharmony_ci 11662306a36Sopenharmony_cistruct atmel_aes_ctr_ctx { 11762306a36Sopenharmony_ci struct atmel_aes_base_ctx base; 11862306a36Sopenharmony_ci 11962306a36Sopenharmony_ci __be32 iv[AES_BLOCK_SIZE / sizeof(u32)]; 12062306a36Sopenharmony_ci size_t offset; 12162306a36Sopenharmony_ci struct scatterlist src[2]; 12262306a36Sopenharmony_ci struct scatterlist dst[2]; 12362306a36Sopenharmony_ci u32 blocks; 12462306a36Sopenharmony_ci}; 12562306a36Sopenharmony_ci 12662306a36Sopenharmony_cistruct atmel_aes_gcm_ctx { 12762306a36Sopenharmony_ci struct atmel_aes_base_ctx base; 12862306a36Sopenharmony_ci 12962306a36Sopenharmony_ci struct scatterlist src[2]; 13062306a36Sopenharmony_ci struct scatterlist dst[2]; 13162306a36Sopenharmony_ci 13262306a36Sopenharmony_ci __be32 j0[AES_BLOCK_SIZE / sizeof(u32)]; 13362306a36Sopenharmony_ci u32 tag[AES_BLOCK_SIZE / sizeof(u32)]; 13462306a36Sopenharmony_ci __be32 ghash[AES_BLOCK_SIZE / sizeof(u32)]; 13562306a36Sopenharmony_ci size_t textlen; 13662306a36Sopenharmony_ci 13762306a36Sopenharmony_ci const __be32 *ghash_in; 13862306a36Sopenharmony_ci __be32 *ghash_out; 13962306a36Sopenharmony_ci atmel_aes_fn_t ghash_resume; 14062306a36Sopenharmony_ci}; 14162306a36Sopenharmony_ci 14262306a36Sopenharmony_cistruct atmel_aes_xts_ctx { 14362306a36Sopenharmony_ci struct atmel_aes_base_ctx base; 14462306a36Sopenharmony_ci 14562306a36Sopenharmony_ci u32 key2[AES_KEYSIZE_256 / sizeof(u32)]; 14662306a36Sopenharmony_ci struct crypto_skcipher *fallback_tfm; 14762306a36Sopenharmony_ci}; 14862306a36Sopenharmony_ci 14962306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 15062306a36Sopenharmony_cistruct atmel_aes_authenc_ctx { 15162306a36Sopenharmony_ci struct atmel_aes_base_ctx base; 15262306a36Sopenharmony_ci struct atmel_sha_authenc_ctx *auth; 15362306a36Sopenharmony_ci}; 15462306a36Sopenharmony_ci#endif 15562306a36Sopenharmony_ci 15662306a36Sopenharmony_cistruct atmel_aes_reqctx { 15762306a36Sopenharmony_ci unsigned long mode; 15862306a36Sopenharmony_ci u8 lastc[AES_BLOCK_SIZE]; 15962306a36Sopenharmony_ci struct skcipher_request fallback_req; 16062306a36Sopenharmony_ci}; 16162306a36Sopenharmony_ci 16262306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 16362306a36Sopenharmony_cistruct atmel_aes_authenc_reqctx { 16462306a36Sopenharmony_ci struct atmel_aes_reqctx base; 16562306a36Sopenharmony_ci 16662306a36Sopenharmony_ci struct scatterlist src[2]; 16762306a36Sopenharmony_ci struct scatterlist dst[2]; 16862306a36Sopenharmony_ci size_t textlen; 16962306a36Sopenharmony_ci u32 digest[SHA512_DIGEST_SIZE / sizeof(u32)]; 17062306a36Sopenharmony_ci 17162306a36Sopenharmony_ci /* auth_req MUST be place last. */ 17262306a36Sopenharmony_ci struct ahash_request auth_req; 17362306a36Sopenharmony_ci}; 17462306a36Sopenharmony_ci#endif 17562306a36Sopenharmony_ci 17662306a36Sopenharmony_cistruct atmel_aes_dma { 17762306a36Sopenharmony_ci struct dma_chan *chan; 17862306a36Sopenharmony_ci struct scatterlist *sg; 17962306a36Sopenharmony_ci int nents; 18062306a36Sopenharmony_ci unsigned int remainder; 18162306a36Sopenharmony_ci unsigned int sg_len; 18262306a36Sopenharmony_ci}; 18362306a36Sopenharmony_ci 18462306a36Sopenharmony_cistruct atmel_aes_dev { 18562306a36Sopenharmony_ci struct list_head list; 18662306a36Sopenharmony_ci unsigned long phys_base; 18762306a36Sopenharmony_ci void __iomem *io_base; 18862306a36Sopenharmony_ci 18962306a36Sopenharmony_ci struct crypto_async_request *areq; 19062306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx; 19162306a36Sopenharmony_ci 19262306a36Sopenharmony_ci bool is_async; 19362306a36Sopenharmony_ci atmel_aes_fn_t resume; 19462306a36Sopenharmony_ci atmel_aes_fn_t cpu_transfer_complete; 19562306a36Sopenharmony_ci 19662306a36Sopenharmony_ci struct device *dev; 19762306a36Sopenharmony_ci struct clk *iclk; 19862306a36Sopenharmony_ci int irq; 19962306a36Sopenharmony_ci 20062306a36Sopenharmony_ci unsigned long flags; 20162306a36Sopenharmony_ci 20262306a36Sopenharmony_ci spinlock_t lock; 20362306a36Sopenharmony_ci struct crypto_queue queue; 20462306a36Sopenharmony_ci 20562306a36Sopenharmony_ci struct tasklet_struct done_task; 20662306a36Sopenharmony_ci struct tasklet_struct queue_task; 20762306a36Sopenharmony_ci 20862306a36Sopenharmony_ci size_t total; 20962306a36Sopenharmony_ci size_t datalen; 21062306a36Sopenharmony_ci u32 *data; 21162306a36Sopenharmony_ci 21262306a36Sopenharmony_ci struct atmel_aes_dma src; 21362306a36Sopenharmony_ci struct atmel_aes_dma dst; 21462306a36Sopenharmony_ci 21562306a36Sopenharmony_ci size_t buflen; 21662306a36Sopenharmony_ci void *buf; 21762306a36Sopenharmony_ci struct scatterlist aligned_sg; 21862306a36Sopenharmony_ci struct scatterlist *real_dst; 21962306a36Sopenharmony_ci 22062306a36Sopenharmony_ci struct atmel_aes_caps caps; 22162306a36Sopenharmony_ci 22262306a36Sopenharmony_ci u32 hw_version; 22362306a36Sopenharmony_ci}; 22462306a36Sopenharmony_ci 22562306a36Sopenharmony_cistruct atmel_aes_drv { 22662306a36Sopenharmony_ci struct list_head dev_list; 22762306a36Sopenharmony_ci spinlock_t lock; 22862306a36Sopenharmony_ci}; 22962306a36Sopenharmony_ci 23062306a36Sopenharmony_cistatic struct atmel_aes_drv atmel_aes = { 23162306a36Sopenharmony_ci .dev_list = LIST_HEAD_INIT(atmel_aes.dev_list), 23262306a36Sopenharmony_ci .lock = __SPIN_LOCK_UNLOCKED(atmel_aes.lock), 23362306a36Sopenharmony_ci}; 23462306a36Sopenharmony_ci 23562306a36Sopenharmony_ci#ifdef VERBOSE_DEBUG 23662306a36Sopenharmony_cistatic const char *atmel_aes_reg_name(u32 offset, char *tmp, size_t sz) 23762306a36Sopenharmony_ci{ 23862306a36Sopenharmony_ci switch (offset) { 23962306a36Sopenharmony_ci case AES_CR: 24062306a36Sopenharmony_ci return "CR"; 24162306a36Sopenharmony_ci 24262306a36Sopenharmony_ci case AES_MR: 24362306a36Sopenharmony_ci return "MR"; 24462306a36Sopenharmony_ci 24562306a36Sopenharmony_ci case AES_ISR: 24662306a36Sopenharmony_ci return "ISR"; 24762306a36Sopenharmony_ci 24862306a36Sopenharmony_ci case AES_IMR: 24962306a36Sopenharmony_ci return "IMR"; 25062306a36Sopenharmony_ci 25162306a36Sopenharmony_ci case AES_IER: 25262306a36Sopenharmony_ci return "IER"; 25362306a36Sopenharmony_ci 25462306a36Sopenharmony_ci case AES_IDR: 25562306a36Sopenharmony_ci return "IDR"; 25662306a36Sopenharmony_ci 25762306a36Sopenharmony_ci case AES_KEYWR(0): 25862306a36Sopenharmony_ci case AES_KEYWR(1): 25962306a36Sopenharmony_ci case AES_KEYWR(2): 26062306a36Sopenharmony_ci case AES_KEYWR(3): 26162306a36Sopenharmony_ci case AES_KEYWR(4): 26262306a36Sopenharmony_ci case AES_KEYWR(5): 26362306a36Sopenharmony_ci case AES_KEYWR(6): 26462306a36Sopenharmony_ci case AES_KEYWR(7): 26562306a36Sopenharmony_ci snprintf(tmp, sz, "KEYWR[%u]", (offset - AES_KEYWR(0)) >> 2); 26662306a36Sopenharmony_ci break; 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_ci case AES_IDATAR(0): 26962306a36Sopenharmony_ci case AES_IDATAR(1): 27062306a36Sopenharmony_ci case AES_IDATAR(2): 27162306a36Sopenharmony_ci case AES_IDATAR(3): 27262306a36Sopenharmony_ci snprintf(tmp, sz, "IDATAR[%u]", (offset - AES_IDATAR(0)) >> 2); 27362306a36Sopenharmony_ci break; 27462306a36Sopenharmony_ci 27562306a36Sopenharmony_ci case AES_ODATAR(0): 27662306a36Sopenharmony_ci case AES_ODATAR(1): 27762306a36Sopenharmony_ci case AES_ODATAR(2): 27862306a36Sopenharmony_ci case AES_ODATAR(3): 27962306a36Sopenharmony_ci snprintf(tmp, sz, "ODATAR[%u]", (offset - AES_ODATAR(0)) >> 2); 28062306a36Sopenharmony_ci break; 28162306a36Sopenharmony_ci 28262306a36Sopenharmony_ci case AES_IVR(0): 28362306a36Sopenharmony_ci case AES_IVR(1): 28462306a36Sopenharmony_ci case AES_IVR(2): 28562306a36Sopenharmony_ci case AES_IVR(3): 28662306a36Sopenharmony_ci snprintf(tmp, sz, "IVR[%u]", (offset - AES_IVR(0)) >> 2); 28762306a36Sopenharmony_ci break; 28862306a36Sopenharmony_ci 28962306a36Sopenharmony_ci case AES_AADLENR: 29062306a36Sopenharmony_ci return "AADLENR"; 29162306a36Sopenharmony_ci 29262306a36Sopenharmony_ci case AES_CLENR: 29362306a36Sopenharmony_ci return "CLENR"; 29462306a36Sopenharmony_ci 29562306a36Sopenharmony_ci case AES_GHASHR(0): 29662306a36Sopenharmony_ci case AES_GHASHR(1): 29762306a36Sopenharmony_ci case AES_GHASHR(2): 29862306a36Sopenharmony_ci case AES_GHASHR(3): 29962306a36Sopenharmony_ci snprintf(tmp, sz, "GHASHR[%u]", (offset - AES_GHASHR(0)) >> 2); 30062306a36Sopenharmony_ci break; 30162306a36Sopenharmony_ci 30262306a36Sopenharmony_ci case AES_TAGR(0): 30362306a36Sopenharmony_ci case AES_TAGR(1): 30462306a36Sopenharmony_ci case AES_TAGR(2): 30562306a36Sopenharmony_ci case AES_TAGR(3): 30662306a36Sopenharmony_ci snprintf(tmp, sz, "TAGR[%u]", (offset - AES_TAGR(0)) >> 2); 30762306a36Sopenharmony_ci break; 30862306a36Sopenharmony_ci 30962306a36Sopenharmony_ci case AES_CTRR: 31062306a36Sopenharmony_ci return "CTRR"; 31162306a36Sopenharmony_ci 31262306a36Sopenharmony_ci case AES_GCMHR(0): 31362306a36Sopenharmony_ci case AES_GCMHR(1): 31462306a36Sopenharmony_ci case AES_GCMHR(2): 31562306a36Sopenharmony_ci case AES_GCMHR(3): 31662306a36Sopenharmony_ci snprintf(tmp, sz, "GCMHR[%u]", (offset - AES_GCMHR(0)) >> 2); 31762306a36Sopenharmony_ci break; 31862306a36Sopenharmony_ci 31962306a36Sopenharmony_ci case AES_EMR: 32062306a36Sopenharmony_ci return "EMR"; 32162306a36Sopenharmony_ci 32262306a36Sopenharmony_ci case AES_TWR(0): 32362306a36Sopenharmony_ci case AES_TWR(1): 32462306a36Sopenharmony_ci case AES_TWR(2): 32562306a36Sopenharmony_ci case AES_TWR(3): 32662306a36Sopenharmony_ci snprintf(tmp, sz, "TWR[%u]", (offset - AES_TWR(0)) >> 2); 32762306a36Sopenharmony_ci break; 32862306a36Sopenharmony_ci 32962306a36Sopenharmony_ci case AES_ALPHAR(0): 33062306a36Sopenharmony_ci case AES_ALPHAR(1): 33162306a36Sopenharmony_ci case AES_ALPHAR(2): 33262306a36Sopenharmony_ci case AES_ALPHAR(3): 33362306a36Sopenharmony_ci snprintf(tmp, sz, "ALPHAR[%u]", (offset - AES_ALPHAR(0)) >> 2); 33462306a36Sopenharmony_ci break; 33562306a36Sopenharmony_ci 33662306a36Sopenharmony_ci default: 33762306a36Sopenharmony_ci snprintf(tmp, sz, "0x%02x", offset); 33862306a36Sopenharmony_ci break; 33962306a36Sopenharmony_ci } 34062306a36Sopenharmony_ci 34162306a36Sopenharmony_ci return tmp; 34262306a36Sopenharmony_ci} 34362306a36Sopenharmony_ci#endif /* VERBOSE_DEBUG */ 34462306a36Sopenharmony_ci 34562306a36Sopenharmony_ci/* Shared functions */ 34662306a36Sopenharmony_ci 34762306a36Sopenharmony_cistatic inline u32 atmel_aes_read(struct atmel_aes_dev *dd, u32 offset) 34862306a36Sopenharmony_ci{ 34962306a36Sopenharmony_ci u32 value = readl_relaxed(dd->io_base + offset); 35062306a36Sopenharmony_ci 35162306a36Sopenharmony_ci#ifdef VERBOSE_DEBUG 35262306a36Sopenharmony_ci if (dd->flags & AES_FLAGS_DUMP_REG) { 35362306a36Sopenharmony_ci char tmp[16]; 35462306a36Sopenharmony_ci 35562306a36Sopenharmony_ci dev_vdbg(dd->dev, "read 0x%08x from %s\n", value, 35662306a36Sopenharmony_ci atmel_aes_reg_name(offset, tmp, sizeof(tmp))); 35762306a36Sopenharmony_ci } 35862306a36Sopenharmony_ci#endif /* VERBOSE_DEBUG */ 35962306a36Sopenharmony_ci 36062306a36Sopenharmony_ci return value; 36162306a36Sopenharmony_ci} 36262306a36Sopenharmony_ci 36362306a36Sopenharmony_cistatic inline void atmel_aes_write(struct atmel_aes_dev *dd, 36462306a36Sopenharmony_ci u32 offset, u32 value) 36562306a36Sopenharmony_ci{ 36662306a36Sopenharmony_ci#ifdef VERBOSE_DEBUG 36762306a36Sopenharmony_ci if (dd->flags & AES_FLAGS_DUMP_REG) { 36862306a36Sopenharmony_ci char tmp[16]; 36962306a36Sopenharmony_ci 37062306a36Sopenharmony_ci dev_vdbg(dd->dev, "write 0x%08x into %s\n", value, 37162306a36Sopenharmony_ci atmel_aes_reg_name(offset, tmp, sizeof(tmp))); 37262306a36Sopenharmony_ci } 37362306a36Sopenharmony_ci#endif /* VERBOSE_DEBUG */ 37462306a36Sopenharmony_ci 37562306a36Sopenharmony_ci writel_relaxed(value, dd->io_base + offset); 37662306a36Sopenharmony_ci} 37762306a36Sopenharmony_ci 37862306a36Sopenharmony_cistatic void atmel_aes_read_n(struct atmel_aes_dev *dd, u32 offset, 37962306a36Sopenharmony_ci u32 *value, int count) 38062306a36Sopenharmony_ci{ 38162306a36Sopenharmony_ci for (; count--; value++, offset += 4) 38262306a36Sopenharmony_ci *value = atmel_aes_read(dd, offset); 38362306a36Sopenharmony_ci} 38462306a36Sopenharmony_ci 38562306a36Sopenharmony_cistatic void atmel_aes_write_n(struct atmel_aes_dev *dd, u32 offset, 38662306a36Sopenharmony_ci const u32 *value, int count) 38762306a36Sopenharmony_ci{ 38862306a36Sopenharmony_ci for (; count--; value++, offset += 4) 38962306a36Sopenharmony_ci atmel_aes_write(dd, offset, *value); 39062306a36Sopenharmony_ci} 39162306a36Sopenharmony_ci 39262306a36Sopenharmony_cistatic inline void atmel_aes_read_block(struct atmel_aes_dev *dd, u32 offset, 39362306a36Sopenharmony_ci void *value) 39462306a36Sopenharmony_ci{ 39562306a36Sopenharmony_ci atmel_aes_read_n(dd, offset, value, SIZE_IN_WORDS(AES_BLOCK_SIZE)); 39662306a36Sopenharmony_ci} 39762306a36Sopenharmony_ci 39862306a36Sopenharmony_cistatic inline void atmel_aes_write_block(struct atmel_aes_dev *dd, u32 offset, 39962306a36Sopenharmony_ci const void *value) 40062306a36Sopenharmony_ci{ 40162306a36Sopenharmony_ci atmel_aes_write_n(dd, offset, value, SIZE_IN_WORDS(AES_BLOCK_SIZE)); 40262306a36Sopenharmony_ci} 40362306a36Sopenharmony_ci 40462306a36Sopenharmony_cistatic inline int atmel_aes_wait_for_data_ready(struct atmel_aes_dev *dd, 40562306a36Sopenharmony_ci atmel_aes_fn_t resume) 40662306a36Sopenharmony_ci{ 40762306a36Sopenharmony_ci u32 isr = atmel_aes_read(dd, AES_ISR); 40862306a36Sopenharmony_ci 40962306a36Sopenharmony_ci if (unlikely(isr & AES_INT_DATARDY)) 41062306a36Sopenharmony_ci return resume(dd); 41162306a36Sopenharmony_ci 41262306a36Sopenharmony_ci dd->resume = resume; 41362306a36Sopenharmony_ci atmel_aes_write(dd, AES_IER, AES_INT_DATARDY); 41462306a36Sopenharmony_ci return -EINPROGRESS; 41562306a36Sopenharmony_ci} 41662306a36Sopenharmony_ci 41762306a36Sopenharmony_cistatic inline size_t atmel_aes_padlen(size_t len, size_t block_size) 41862306a36Sopenharmony_ci{ 41962306a36Sopenharmony_ci len &= block_size - 1; 42062306a36Sopenharmony_ci return len ? block_size - len : 0; 42162306a36Sopenharmony_ci} 42262306a36Sopenharmony_ci 42362306a36Sopenharmony_cistatic struct atmel_aes_dev *atmel_aes_dev_alloc(struct atmel_aes_base_ctx *ctx) 42462306a36Sopenharmony_ci{ 42562306a36Sopenharmony_ci struct atmel_aes_dev *aes_dd; 42662306a36Sopenharmony_ci 42762306a36Sopenharmony_ci spin_lock_bh(&atmel_aes.lock); 42862306a36Sopenharmony_ci /* One AES IP per SoC. */ 42962306a36Sopenharmony_ci aes_dd = list_first_entry_or_null(&atmel_aes.dev_list, 43062306a36Sopenharmony_ci struct atmel_aes_dev, list); 43162306a36Sopenharmony_ci spin_unlock_bh(&atmel_aes.lock); 43262306a36Sopenharmony_ci return aes_dd; 43362306a36Sopenharmony_ci} 43462306a36Sopenharmony_ci 43562306a36Sopenharmony_cistatic int atmel_aes_hw_init(struct atmel_aes_dev *dd) 43662306a36Sopenharmony_ci{ 43762306a36Sopenharmony_ci int err; 43862306a36Sopenharmony_ci 43962306a36Sopenharmony_ci err = clk_enable(dd->iclk); 44062306a36Sopenharmony_ci if (err) 44162306a36Sopenharmony_ci return err; 44262306a36Sopenharmony_ci 44362306a36Sopenharmony_ci atmel_aes_write(dd, AES_CR, AES_CR_SWRST); 44462306a36Sopenharmony_ci atmel_aes_write(dd, AES_MR, 0xE << AES_MR_CKEY_OFFSET); 44562306a36Sopenharmony_ci 44662306a36Sopenharmony_ci return 0; 44762306a36Sopenharmony_ci} 44862306a36Sopenharmony_ci 44962306a36Sopenharmony_cistatic inline unsigned int atmel_aes_get_version(struct atmel_aes_dev *dd) 45062306a36Sopenharmony_ci{ 45162306a36Sopenharmony_ci return atmel_aes_read(dd, AES_HW_VERSION) & 0x00000fff; 45262306a36Sopenharmony_ci} 45362306a36Sopenharmony_ci 45462306a36Sopenharmony_cistatic int atmel_aes_hw_version_init(struct atmel_aes_dev *dd) 45562306a36Sopenharmony_ci{ 45662306a36Sopenharmony_ci int err; 45762306a36Sopenharmony_ci 45862306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 45962306a36Sopenharmony_ci if (err) 46062306a36Sopenharmony_ci return err; 46162306a36Sopenharmony_ci 46262306a36Sopenharmony_ci dd->hw_version = atmel_aes_get_version(dd); 46362306a36Sopenharmony_ci 46462306a36Sopenharmony_ci dev_info(dd->dev, "version: 0x%x\n", dd->hw_version); 46562306a36Sopenharmony_ci 46662306a36Sopenharmony_ci clk_disable(dd->iclk); 46762306a36Sopenharmony_ci return 0; 46862306a36Sopenharmony_ci} 46962306a36Sopenharmony_ci 47062306a36Sopenharmony_cistatic inline void atmel_aes_set_mode(struct atmel_aes_dev *dd, 47162306a36Sopenharmony_ci const struct atmel_aes_reqctx *rctx) 47262306a36Sopenharmony_ci{ 47362306a36Sopenharmony_ci /* Clear all but persistent flags and set request flags. */ 47462306a36Sopenharmony_ci dd->flags = (dd->flags & AES_FLAGS_PERSISTENT) | rctx->mode; 47562306a36Sopenharmony_ci} 47662306a36Sopenharmony_ci 47762306a36Sopenharmony_cistatic inline bool atmel_aes_is_encrypt(const struct atmel_aes_dev *dd) 47862306a36Sopenharmony_ci{ 47962306a36Sopenharmony_ci return (dd->flags & AES_FLAGS_ENCRYPT); 48062306a36Sopenharmony_ci} 48162306a36Sopenharmony_ci 48262306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 48362306a36Sopenharmony_cistatic void atmel_aes_authenc_complete(struct atmel_aes_dev *dd, int err); 48462306a36Sopenharmony_ci#endif 48562306a36Sopenharmony_ci 48662306a36Sopenharmony_cistatic void atmel_aes_set_iv_as_last_ciphertext_block(struct atmel_aes_dev *dd) 48762306a36Sopenharmony_ci{ 48862306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 48962306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 49062306a36Sopenharmony_ci struct crypto_skcipher *skcipher = crypto_skcipher_reqtfm(req); 49162306a36Sopenharmony_ci unsigned int ivsize = crypto_skcipher_ivsize(skcipher); 49262306a36Sopenharmony_ci 49362306a36Sopenharmony_ci if (req->cryptlen < ivsize) 49462306a36Sopenharmony_ci return; 49562306a36Sopenharmony_ci 49662306a36Sopenharmony_ci if (rctx->mode & AES_FLAGS_ENCRYPT) 49762306a36Sopenharmony_ci scatterwalk_map_and_copy(req->iv, req->dst, 49862306a36Sopenharmony_ci req->cryptlen - ivsize, ivsize, 0); 49962306a36Sopenharmony_ci else 50062306a36Sopenharmony_ci memcpy(req->iv, rctx->lastc, ivsize); 50162306a36Sopenharmony_ci} 50262306a36Sopenharmony_ci 50362306a36Sopenharmony_cistatic inline struct atmel_aes_ctr_ctx * 50462306a36Sopenharmony_ciatmel_aes_ctr_ctx_cast(struct atmel_aes_base_ctx *ctx) 50562306a36Sopenharmony_ci{ 50662306a36Sopenharmony_ci return container_of(ctx, struct atmel_aes_ctr_ctx, base); 50762306a36Sopenharmony_ci} 50862306a36Sopenharmony_ci 50962306a36Sopenharmony_cistatic void atmel_aes_ctr_update_req_iv(struct atmel_aes_dev *dd) 51062306a36Sopenharmony_ci{ 51162306a36Sopenharmony_ci struct atmel_aes_ctr_ctx *ctx = atmel_aes_ctr_ctx_cast(dd->ctx); 51262306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 51362306a36Sopenharmony_ci struct crypto_skcipher *skcipher = crypto_skcipher_reqtfm(req); 51462306a36Sopenharmony_ci unsigned int ivsize = crypto_skcipher_ivsize(skcipher); 51562306a36Sopenharmony_ci int i; 51662306a36Sopenharmony_ci 51762306a36Sopenharmony_ci /* 51862306a36Sopenharmony_ci * The CTR transfer works in fragments of data of maximum 1 MByte 51962306a36Sopenharmony_ci * because of the 16 bit CTR counter embedded in the IP. When reaching 52062306a36Sopenharmony_ci * here, ctx->blocks contains the number of blocks of the last fragment 52162306a36Sopenharmony_ci * processed, there is no need to explicit cast it to u16. 52262306a36Sopenharmony_ci */ 52362306a36Sopenharmony_ci for (i = 0; i < ctx->blocks; i++) 52462306a36Sopenharmony_ci crypto_inc((u8 *)ctx->iv, AES_BLOCK_SIZE); 52562306a36Sopenharmony_ci 52662306a36Sopenharmony_ci memcpy(req->iv, ctx->iv, ivsize); 52762306a36Sopenharmony_ci} 52862306a36Sopenharmony_ci 52962306a36Sopenharmony_cistatic inline int atmel_aes_complete(struct atmel_aes_dev *dd, int err) 53062306a36Sopenharmony_ci{ 53162306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 53262306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 53362306a36Sopenharmony_ci 53462306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 53562306a36Sopenharmony_ci if (dd->ctx->is_aead) 53662306a36Sopenharmony_ci atmel_aes_authenc_complete(dd, err); 53762306a36Sopenharmony_ci#endif 53862306a36Sopenharmony_ci 53962306a36Sopenharmony_ci clk_disable(dd->iclk); 54062306a36Sopenharmony_ci dd->flags &= ~AES_FLAGS_BUSY; 54162306a36Sopenharmony_ci 54262306a36Sopenharmony_ci if (!err && !dd->ctx->is_aead && 54362306a36Sopenharmony_ci (rctx->mode & AES_FLAGS_OPMODE_MASK) != AES_FLAGS_ECB) { 54462306a36Sopenharmony_ci if ((rctx->mode & AES_FLAGS_OPMODE_MASK) != AES_FLAGS_CTR) 54562306a36Sopenharmony_ci atmel_aes_set_iv_as_last_ciphertext_block(dd); 54662306a36Sopenharmony_ci else 54762306a36Sopenharmony_ci atmel_aes_ctr_update_req_iv(dd); 54862306a36Sopenharmony_ci } 54962306a36Sopenharmony_ci 55062306a36Sopenharmony_ci if (dd->is_async) 55162306a36Sopenharmony_ci crypto_request_complete(dd->areq, err); 55262306a36Sopenharmony_ci 55362306a36Sopenharmony_ci tasklet_schedule(&dd->queue_task); 55462306a36Sopenharmony_ci 55562306a36Sopenharmony_ci return err; 55662306a36Sopenharmony_ci} 55762306a36Sopenharmony_ci 55862306a36Sopenharmony_cistatic void atmel_aes_write_ctrl_key(struct atmel_aes_dev *dd, bool use_dma, 55962306a36Sopenharmony_ci const __be32 *iv, const u32 *key, int keylen) 56062306a36Sopenharmony_ci{ 56162306a36Sopenharmony_ci u32 valmr = 0; 56262306a36Sopenharmony_ci 56362306a36Sopenharmony_ci /* MR register must be set before IV registers */ 56462306a36Sopenharmony_ci if (keylen == AES_KEYSIZE_128) 56562306a36Sopenharmony_ci valmr |= AES_MR_KEYSIZE_128; 56662306a36Sopenharmony_ci else if (keylen == AES_KEYSIZE_192) 56762306a36Sopenharmony_ci valmr |= AES_MR_KEYSIZE_192; 56862306a36Sopenharmony_ci else 56962306a36Sopenharmony_ci valmr |= AES_MR_KEYSIZE_256; 57062306a36Sopenharmony_ci 57162306a36Sopenharmony_ci valmr |= dd->flags & AES_FLAGS_MODE_MASK; 57262306a36Sopenharmony_ci 57362306a36Sopenharmony_ci if (use_dma) { 57462306a36Sopenharmony_ci valmr |= AES_MR_SMOD_IDATAR0; 57562306a36Sopenharmony_ci if (dd->caps.has_dualbuff) 57662306a36Sopenharmony_ci valmr |= AES_MR_DUALBUFF; 57762306a36Sopenharmony_ci } else { 57862306a36Sopenharmony_ci valmr |= AES_MR_SMOD_AUTO; 57962306a36Sopenharmony_ci } 58062306a36Sopenharmony_ci 58162306a36Sopenharmony_ci atmel_aes_write(dd, AES_MR, valmr); 58262306a36Sopenharmony_ci 58362306a36Sopenharmony_ci atmel_aes_write_n(dd, AES_KEYWR(0), key, SIZE_IN_WORDS(keylen)); 58462306a36Sopenharmony_ci 58562306a36Sopenharmony_ci if (iv && (valmr & AES_MR_OPMOD_MASK) != AES_MR_OPMOD_ECB) 58662306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IVR(0), iv); 58762306a36Sopenharmony_ci} 58862306a36Sopenharmony_ci 58962306a36Sopenharmony_cistatic inline void atmel_aes_write_ctrl(struct atmel_aes_dev *dd, bool use_dma, 59062306a36Sopenharmony_ci const __be32 *iv) 59162306a36Sopenharmony_ci 59262306a36Sopenharmony_ci{ 59362306a36Sopenharmony_ci atmel_aes_write_ctrl_key(dd, use_dma, iv, 59462306a36Sopenharmony_ci dd->ctx->key, dd->ctx->keylen); 59562306a36Sopenharmony_ci} 59662306a36Sopenharmony_ci 59762306a36Sopenharmony_ci/* CPU transfer */ 59862306a36Sopenharmony_ci 59962306a36Sopenharmony_cistatic int atmel_aes_cpu_transfer(struct atmel_aes_dev *dd) 60062306a36Sopenharmony_ci{ 60162306a36Sopenharmony_ci int err = 0; 60262306a36Sopenharmony_ci u32 isr; 60362306a36Sopenharmony_ci 60462306a36Sopenharmony_ci for (;;) { 60562306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_ODATAR(0), dd->data); 60662306a36Sopenharmony_ci dd->data += 4; 60762306a36Sopenharmony_ci dd->datalen -= AES_BLOCK_SIZE; 60862306a36Sopenharmony_ci 60962306a36Sopenharmony_ci if (dd->datalen < AES_BLOCK_SIZE) 61062306a36Sopenharmony_ci break; 61162306a36Sopenharmony_ci 61262306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), dd->data); 61362306a36Sopenharmony_ci 61462306a36Sopenharmony_ci isr = atmel_aes_read(dd, AES_ISR); 61562306a36Sopenharmony_ci if (!(isr & AES_INT_DATARDY)) { 61662306a36Sopenharmony_ci dd->resume = atmel_aes_cpu_transfer; 61762306a36Sopenharmony_ci atmel_aes_write(dd, AES_IER, AES_INT_DATARDY); 61862306a36Sopenharmony_ci return -EINPROGRESS; 61962306a36Sopenharmony_ci } 62062306a36Sopenharmony_ci } 62162306a36Sopenharmony_ci 62262306a36Sopenharmony_ci if (!sg_copy_from_buffer(dd->real_dst, sg_nents(dd->real_dst), 62362306a36Sopenharmony_ci dd->buf, dd->total)) 62462306a36Sopenharmony_ci err = -EINVAL; 62562306a36Sopenharmony_ci 62662306a36Sopenharmony_ci if (err) 62762306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 62862306a36Sopenharmony_ci 62962306a36Sopenharmony_ci return dd->cpu_transfer_complete(dd); 63062306a36Sopenharmony_ci} 63162306a36Sopenharmony_ci 63262306a36Sopenharmony_cistatic int atmel_aes_cpu_start(struct atmel_aes_dev *dd, 63362306a36Sopenharmony_ci struct scatterlist *src, 63462306a36Sopenharmony_ci struct scatterlist *dst, 63562306a36Sopenharmony_ci size_t len, 63662306a36Sopenharmony_ci atmel_aes_fn_t resume) 63762306a36Sopenharmony_ci{ 63862306a36Sopenharmony_ci size_t padlen = atmel_aes_padlen(len, AES_BLOCK_SIZE); 63962306a36Sopenharmony_ci 64062306a36Sopenharmony_ci if (unlikely(len == 0)) 64162306a36Sopenharmony_ci return -EINVAL; 64262306a36Sopenharmony_ci 64362306a36Sopenharmony_ci sg_copy_to_buffer(src, sg_nents(src), dd->buf, len); 64462306a36Sopenharmony_ci 64562306a36Sopenharmony_ci dd->total = len; 64662306a36Sopenharmony_ci dd->real_dst = dst; 64762306a36Sopenharmony_ci dd->cpu_transfer_complete = resume; 64862306a36Sopenharmony_ci dd->datalen = len + padlen; 64962306a36Sopenharmony_ci dd->data = (u32 *)dd->buf; 65062306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), dd->data); 65162306a36Sopenharmony_ci return atmel_aes_wait_for_data_ready(dd, atmel_aes_cpu_transfer); 65262306a36Sopenharmony_ci} 65362306a36Sopenharmony_ci 65462306a36Sopenharmony_ci 65562306a36Sopenharmony_ci/* DMA transfer */ 65662306a36Sopenharmony_ci 65762306a36Sopenharmony_cistatic void atmel_aes_dma_callback(void *data); 65862306a36Sopenharmony_ci 65962306a36Sopenharmony_cistatic bool atmel_aes_check_aligned(struct atmel_aes_dev *dd, 66062306a36Sopenharmony_ci struct scatterlist *sg, 66162306a36Sopenharmony_ci size_t len, 66262306a36Sopenharmony_ci struct atmel_aes_dma *dma) 66362306a36Sopenharmony_ci{ 66462306a36Sopenharmony_ci int nents; 66562306a36Sopenharmony_ci 66662306a36Sopenharmony_ci if (!IS_ALIGNED(len, dd->ctx->block_size)) 66762306a36Sopenharmony_ci return false; 66862306a36Sopenharmony_ci 66962306a36Sopenharmony_ci for (nents = 0; sg; sg = sg_next(sg), ++nents) { 67062306a36Sopenharmony_ci if (!IS_ALIGNED(sg->offset, sizeof(u32))) 67162306a36Sopenharmony_ci return false; 67262306a36Sopenharmony_ci 67362306a36Sopenharmony_ci if (len <= sg->length) { 67462306a36Sopenharmony_ci if (!IS_ALIGNED(len, dd->ctx->block_size)) 67562306a36Sopenharmony_ci return false; 67662306a36Sopenharmony_ci 67762306a36Sopenharmony_ci dma->nents = nents+1; 67862306a36Sopenharmony_ci dma->remainder = sg->length - len; 67962306a36Sopenharmony_ci sg->length = len; 68062306a36Sopenharmony_ci return true; 68162306a36Sopenharmony_ci } 68262306a36Sopenharmony_ci 68362306a36Sopenharmony_ci if (!IS_ALIGNED(sg->length, dd->ctx->block_size)) 68462306a36Sopenharmony_ci return false; 68562306a36Sopenharmony_ci 68662306a36Sopenharmony_ci len -= sg->length; 68762306a36Sopenharmony_ci } 68862306a36Sopenharmony_ci 68962306a36Sopenharmony_ci return false; 69062306a36Sopenharmony_ci} 69162306a36Sopenharmony_ci 69262306a36Sopenharmony_cistatic inline void atmel_aes_restore_sg(const struct atmel_aes_dma *dma) 69362306a36Sopenharmony_ci{ 69462306a36Sopenharmony_ci struct scatterlist *sg = dma->sg; 69562306a36Sopenharmony_ci int nents = dma->nents; 69662306a36Sopenharmony_ci 69762306a36Sopenharmony_ci if (!dma->remainder) 69862306a36Sopenharmony_ci return; 69962306a36Sopenharmony_ci 70062306a36Sopenharmony_ci while (--nents > 0 && sg) 70162306a36Sopenharmony_ci sg = sg_next(sg); 70262306a36Sopenharmony_ci 70362306a36Sopenharmony_ci if (!sg) 70462306a36Sopenharmony_ci return; 70562306a36Sopenharmony_ci 70662306a36Sopenharmony_ci sg->length += dma->remainder; 70762306a36Sopenharmony_ci} 70862306a36Sopenharmony_ci 70962306a36Sopenharmony_cistatic int atmel_aes_map(struct atmel_aes_dev *dd, 71062306a36Sopenharmony_ci struct scatterlist *src, 71162306a36Sopenharmony_ci struct scatterlist *dst, 71262306a36Sopenharmony_ci size_t len) 71362306a36Sopenharmony_ci{ 71462306a36Sopenharmony_ci bool src_aligned, dst_aligned; 71562306a36Sopenharmony_ci size_t padlen; 71662306a36Sopenharmony_ci 71762306a36Sopenharmony_ci dd->total = len; 71862306a36Sopenharmony_ci dd->src.sg = src; 71962306a36Sopenharmony_ci dd->dst.sg = dst; 72062306a36Sopenharmony_ci dd->real_dst = dst; 72162306a36Sopenharmony_ci 72262306a36Sopenharmony_ci src_aligned = atmel_aes_check_aligned(dd, src, len, &dd->src); 72362306a36Sopenharmony_ci if (src == dst) 72462306a36Sopenharmony_ci dst_aligned = src_aligned; 72562306a36Sopenharmony_ci else 72662306a36Sopenharmony_ci dst_aligned = atmel_aes_check_aligned(dd, dst, len, &dd->dst); 72762306a36Sopenharmony_ci if (!src_aligned || !dst_aligned) { 72862306a36Sopenharmony_ci padlen = atmel_aes_padlen(len, dd->ctx->block_size); 72962306a36Sopenharmony_ci 73062306a36Sopenharmony_ci if (dd->buflen < len + padlen) 73162306a36Sopenharmony_ci return -ENOMEM; 73262306a36Sopenharmony_ci 73362306a36Sopenharmony_ci if (!src_aligned) { 73462306a36Sopenharmony_ci sg_copy_to_buffer(src, sg_nents(src), dd->buf, len); 73562306a36Sopenharmony_ci dd->src.sg = &dd->aligned_sg; 73662306a36Sopenharmony_ci dd->src.nents = 1; 73762306a36Sopenharmony_ci dd->src.remainder = 0; 73862306a36Sopenharmony_ci } 73962306a36Sopenharmony_ci 74062306a36Sopenharmony_ci if (!dst_aligned) { 74162306a36Sopenharmony_ci dd->dst.sg = &dd->aligned_sg; 74262306a36Sopenharmony_ci dd->dst.nents = 1; 74362306a36Sopenharmony_ci dd->dst.remainder = 0; 74462306a36Sopenharmony_ci } 74562306a36Sopenharmony_ci 74662306a36Sopenharmony_ci sg_init_table(&dd->aligned_sg, 1); 74762306a36Sopenharmony_ci sg_set_buf(&dd->aligned_sg, dd->buf, len + padlen); 74862306a36Sopenharmony_ci } 74962306a36Sopenharmony_ci 75062306a36Sopenharmony_ci if (dd->src.sg == dd->dst.sg) { 75162306a36Sopenharmony_ci dd->src.sg_len = dma_map_sg(dd->dev, dd->src.sg, dd->src.nents, 75262306a36Sopenharmony_ci DMA_BIDIRECTIONAL); 75362306a36Sopenharmony_ci dd->dst.sg_len = dd->src.sg_len; 75462306a36Sopenharmony_ci if (!dd->src.sg_len) 75562306a36Sopenharmony_ci return -EFAULT; 75662306a36Sopenharmony_ci } else { 75762306a36Sopenharmony_ci dd->src.sg_len = dma_map_sg(dd->dev, dd->src.sg, dd->src.nents, 75862306a36Sopenharmony_ci DMA_TO_DEVICE); 75962306a36Sopenharmony_ci if (!dd->src.sg_len) 76062306a36Sopenharmony_ci return -EFAULT; 76162306a36Sopenharmony_ci 76262306a36Sopenharmony_ci dd->dst.sg_len = dma_map_sg(dd->dev, dd->dst.sg, dd->dst.nents, 76362306a36Sopenharmony_ci DMA_FROM_DEVICE); 76462306a36Sopenharmony_ci if (!dd->dst.sg_len) { 76562306a36Sopenharmony_ci dma_unmap_sg(dd->dev, dd->src.sg, dd->src.nents, 76662306a36Sopenharmony_ci DMA_TO_DEVICE); 76762306a36Sopenharmony_ci return -EFAULT; 76862306a36Sopenharmony_ci } 76962306a36Sopenharmony_ci } 77062306a36Sopenharmony_ci 77162306a36Sopenharmony_ci return 0; 77262306a36Sopenharmony_ci} 77362306a36Sopenharmony_ci 77462306a36Sopenharmony_cistatic void atmel_aes_unmap(struct atmel_aes_dev *dd) 77562306a36Sopenharmony_ci{ 77662306a36Sopenharmony_ci if (dd->src.sg == dd->dst.sg) { 77762306a36Sopenharmony_ci dma_unmap_sg(dd->dev, dd->src.sg, dd->src.nents, 77862306a36Sopenharmony_ci DMA_BIDIRECTIONAL); 77962306a36Sopenharmony_ci 78062306a36Sopenharmony_ci if (dd->src.sg != &dd->aligned_sg) 78162306a36Sopenharmony_ci atmel_aes_restore_sg(&dd->src); 78262306a36Sopenharmony_ci } else { 78362306a36Sopenharmony_ci dma_unmap_sg(dd->dev, dd->dst.sg, dd->dst.nents, 78462306a36Sopenharmony_ci DMA_FROM_DEVICE); 78562306a36Sopenharmony_ci 78662306a36Sopenharmony_ci if (dd->dst.sg != &dd->aligned_sg) 78762306a36Sopenharmony_ci atmel_aes_restore_sg(&dd->dst); 78862306a36Sopenharmony_ci 78962306a36Sopenharmony_ci dma_unmap_sg(dd->dev, dd->src.sg, dd->src.nents, 79062306a36Sopenharmony_ci DMA_TO_DEVICE); 79162306a36Sopenharmony_ci 79262306a36Sopenharmony_ci if (dd->src.sg != &dd->aligned_sg) 79362306a36Sopenharmony_ci atmel_aes_restore_sg(&dd->src); 79462306a36Sopenharmony_ci } 79562306a36Sopenharmony_ci 79662306a36Sopenharmony_ci if (dd->dst.sg == &dd->aligned_sg) 79762306a36Sopenharmony_ci sg_copy_from_buffer(dd->real_dst, sg_nents(dd->real_dst), 79862306a36Sopenharmony_ci dd->buf, dd->total); 79962306a36Sopenharmony_ci} 80062306a36Sopenharmony_ci 80162306a36Sopenharmony_cistatic int atmel_aes_dma_transfer_start(struct atmel_aes_dev *dd, 80262306a36Sopenharmony_ci enum dma_slave_buswidth addr_width, 80362306a36Sopenharmony_ci enum dma_transfer_direction dir, 80462306a36Sopenharmony_ci u32 maxburst) 80562306a36Sopenharmony_ci{ 80662306a36Sopenharmony_ci struct dma_async_tx_descriptor *desc; 80762306a36Sopenharmony_ci struct dma_slave_config config; 80862306a36Sopenharmony_ci dma_async_tx_callback callback; 80962306a36Sopenharmony_ci struct atmel_aes_dma *dma; 81062306a36Sopenharmony_ci int err; 81162306a36Sopenharmony_ci 81262306a36Sopenharmony_ci memset(&config, 0, sizeof(config)); 81362306a36Sopenharmony_ci config.src_addr_width = addr_width; 81462306a36Sopenharmony_ci config.dst_addr_width = addr_width; 81562306a36Sopenharmony_ci config.src_maxburst = maxburst; 81662306a36Sopenharmony_ci config.dst_maxburst = maxburst; 81762306a36Sopenharmony_ci 81862306a36Sopenharmony_ci switch (dir) { 81962306a36Sopenharmony_ci case DMA_MEM_TO_DEV: 82062306a36Sopenharmony_ci dma = &dd->src; 82162306a36Sopenharmony_ci callback = NULL; 82262306a36Sopenharmony_ci config.dst_addr = dd->phys_base + AES_IDATAR(0); 82362306a36Sopenharmony_ci break; 82462306a36Sopenharmony_ci 82562306a36Sopenharmony_ci case DMA_DEV_TO_MEM: 82662306a36Sopenharmony_ci dma = &dd->dst; 82762306a36Sopenharmony_ci callback = atmel_aes_dma_callback; 82862306a36Sopenharmony_ci config.src_addr = dd->phys_base + AES_ODATAR(0); 82962306a36Sopenharmony_ci break; 83062306a36Sopenharmony_ci 83162306a36Sopenharmony_ci default: 83262306a36Sopenharmony_ci return -EINVAL; 83362306a36Sopenharmony_ci } 83462306a36Sopenharmony_ci 83562306a36Sopenharmony_ci err = dmaengine_slave_config(dma->chan, &config); 83662306a36Sopenharmony_ci if (err) 83762306a36Sopenharmony_ci return err; 83862306a36Sopenharmony_ci 83962306a36Sopenharmony_ci desc = dmaengine_prep_slave_sg(dma->chan, dma->sg, dma->sg_len, dir, 84062306a36Sopenharmony_ci DMA_PREP_INTERRUPT | DMA_CTRL_ACK); 84162306a36Sopenharmony_ci if (!desc) 84262306a36Sopenharmony_ci return -ENOMEM; 84362306a36Sopenharmony_ci 84462306a36Sopenharmony_ci desc->callback = callback; 84562306a36Sopenharmony_ci desc->callback_param = dd; 84662306a36Sopenharmony_ci dmaengine_submit(desc); 84762306a36Sopenharmony_ci dma_async_issue_pending(dma->chan); 84862306a36Sopenharmony_ci 84962306a36Sopenharmony_ci return 0; 85062306a36Sopenharmony_ci} 85162306a36Sopenharmony_ci 85262306a36Sopenharmony_cistatic int atmel_aes_dma_start(struct atmel_aes_dev *dd, 85362306a36Sopenharmony_ci struct scatterlist *src, 85462306a36Sopenharmony_ci struct scatterlist *dst, 85562306a36Sopenharmony_ci size_t len, 85662306a36Sopenharmony_ci atmel_aes_fn_t resume) 85762306a36Sopenharmony_ci{ 85862306a36Sopenharmony_ci enum dma_slave_buswidth addr_width; 85962306a36Sopenharmony_ci u32 maxburst; 86062306a36Sopenharmony_ci int err; 86162306a36Sopenharmony_ci 86262306a36Sopenharmony_ci switch (dd->ctx->block_size) { 86362306a36Sopenharmony_ci case CFB8_BLOCK_SIZE: 86462306a36Sopenharmony_ci addr_width = DMA_SLAVE_BUSWIDTH_1_BYTE; 86562306a36Sopenharmony_ci maxburst = 1; 86662306a36Sopenharmony_ci break; 86762306a36Sopenharmony_ci 86862306a36Sopenharmony_ci case CFB16_BLOCK_SIZE: 86962306a36Sopenharmony_ci addr_width = DMA_SLAVE_BUSWIDTH_2_BYTES; 87062306a36Sopenharmony_ci maxburst = 1; 87162306a36Sopenharmony_ci break; 87262306a36Sopenharmony_ci 87362306a36Sopenharmony_ci case CFB32_BLOCK_SIZE: 87462306a36Sopenharmony_ci case CFB64_BLOCK_SIZE: 87562306a36Sopenharmony_ci addr_width = DMA_SLAVE_BUSWIDTH_4_BYTES; 87662306a36Sopenharmony_ci maxburst = 1; 87762306a36Sopenharmony_ci break; 87862306a36Sopenharmony_ci 87962306a36Sopenharmony_ci case AES_BLOCK_SIZE: 88062306a36Sopenharmony_ci addr_width = DMA_SLAVE_BUSWIDTH_4_BYTES; 88162306a36Sopenharmony_ci maxburst = dd->caps.max_burst_size; 88262306a36Sopenharmony_ci break; 88362306a36Sopenharmony_ci 88462306a36Sopenharmony_ci default: 88562306a36Sopenharmony_ci err = -EINVAL; 88662306a36Sopenharmony_ci goto exit; 88762306a36Sopenharmony_ci } 88862306a36Sopenharmony_ci 88962306a36Sopenharmony_ci err = atmel_aes_map(dd, src, dst, len); 89062306a36Sopenharmony_ci if (err) 89162306a36Sopenharmony_ci goto exit; 89262306a36Sopenharmony_ci 89362306a36Sopenharmony_ci dd->resume = resume; 89462306a36Sopenharmony_ci 89562306a36Sopenharmony_ci /* Set output DMA transfer first */ 89662306a36Sopenharmony_ci err = atmel_aes_dma_transfer_start(dd, addr_width, DMA_DEV_TO_MEM, 89762306a36Sopenharmony_ci maxburst); 89862306a36Sopenharmony_ci if (err) 89962306a36Sopenharmony_ci goto unmap; 90062306a36Sopenharmony_ci 90162306a36Sopenharmony_ci /* Then set input DMA transfer */ 90262306a36Sopenharmony_ci err = atmel_aes_dma_transfer_start(dd, addr_width, DMA_MEM_TO_DEV, 90362306a36Sopenharmony_ci maxburst); 90462306a36Sopenharmony_ci if (err) 90562306a36Sopenharmony_ci goto output_transfer_stop; 90662306a36Sopenharmony_ci 90762306a36Sopenharmony_ci return -EINPROGRESS; 90862306a36Sopenharmony_ci 90962306a36Sopenharmony_cioutput_transfer_stop: 91062306a36Sopenharmony_ci dmaengine_terminate_sync(dd->dst.chan); 91162306a36Sopenharmony_ciunmap: 91262306a36Sopenharmony_ci atmel_aes_unmap(dd); 91362306a36Sopenharmony_ciexit: 91462306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 91562306a36Sopenharmony_ci} 91662306a36Sopenharmony_ci 91762306a36Sopenharmony_cistatic void atmel_aes_dma_callback(void *data) 91862306a36Sopenharmony_ci{ 91962306a36Sopenharmony_ci struct atmel_aes_dev *dd = data; 92062306a36Sopenharmony_ci 92162306a36Sopenharmony_ci atmel_aes_unmap(dd); 92262306a36Sopenharmony_ci dd->is_async = true; 92362306a36Sopenharmony_ci (void)dd->resume(dd); 92462306a36Sopenharmony_ci} 92562306a36Sopenharmony_ci 92662306a36Sopenharmony_cistatic int atmel_aes_handle_queue(struct atmel_aes_dev *dd, 92762306a36Sopenharmony_ci struct crypto_async_request *new_areq) 92862306a36Sopenharmony_ci{ 92962306a36Sopenharmony_ci struct crypto_async_request *areq, *backlog; 93062306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx; 93162306a36Sopenharmony_ci unsigned long flags; 93262306a36Sopenharmony_ci bool start_async; 93362306a36Sopenharmony_ci int err, ret = 0; 93462306a36Sopenharmony_ci 93562306a36Sopenharmony_ci spin_lock_irqsave(&dd->lock, flags); 93662306a36Sopenharmony_ci if (new_areq) 93762306a36Sopenharmony_ci ret = crypto_enqueue_request(&dd->queue, new_areq); 93862306a36Sopenharmony_ci if (dd->flags & AES_FLAGS_BUSY) { 93962306a36Sopenharmony_ci spin_unlock_irqrestore(&dd->lock, flags); 94062306a36Sopenharmony_ci return ret; 94162306a36Sopenharmony_ci } 94262306a36Sopenharmony_ci backlog = crypto_get_backlog(&dd->queue); 94362306a36Sopenharmony_ci areq = crypto_dequeue_request(&dd->queue); 94462306a36Sopenharmony_ci if (areq) 94562306a36Sopenharmony_ci dd->flags |= AES_FLAGS_BUSY; 94662306a36Sopenharmony_ci spin_unlock_irqrestore(&dd->lock, flags); 94762306a36Sopenharmony_ci 94862306a36Sopenharmony_ci if (!areq) 94962306a36Sopenharmony_ci return ret; 95062306a36Sopenharmony_ci 95162306a36Sopenharmony_ci if (backlog) 95262306a36Sopenharmony_ci crypto_request_complete(backlog, -EINPROGRESS); 95362306a36Sopenharmony_ci 95462306a36Sopenharmony_ci ctx = crypto_tfm_ctx(areq->tfm); 95562306a36Sopenharmony_ci 95662306a36Sopenharmony_ci dd->areq = areq; 95762306a36Sopenharmony_ci dd->ctx = ctx; 95862306a36Sopenharmony_ci start_async = (areq != new_areq); 95962306a36Sopenharmony_ci dd->is_async = start_async; 96062306a36Sopenharmony_ci 96162306a36Sopenharmony_ci /* WARNING: ctx->start() MAY change dd->is_async. */ 96262306a36Sopenharmony_ci err = ctx->start(dd); 96362306a36Sopenharmony_ci return (start_async) ? ret : err; 96462306a36Sopenharmony_ci} 96562306a36Sopenharmony_ci 96662306a36Sopenharmony_ci 96762306a36Sopenharmony_ci/* AES async block ciphers */ 96862306a36Sopenharmony_ci 96962306a36Sopenharmony_cistatic int atmel_aes_transfer_complete(struct atmel_aes_dev *dd) 97062306a36Sopenharmony_ci{ 97162306a36Sopenharmony_ci return atmel_aes_complete(dd, 0); 97262306a36Sopenharmony_ci} 97362306a36Sopenharmony_ci 97462306a36Sopenharmony_cistatic int atmel_aes_start(struct atmel_aes_dev *dd) 97562306a36Sopenharmony_ci{ 97662306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 97762306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 97862306a36Sopenharmony_ci bool use_dma = (req->cryptlen >= ATMEL_AES_DMA_THRESHOLD || 97962306a36Sopenharmony_ci dd->ctx->block_size != AES_BLOCK_SIZE); 98062306a36Sopenharmony_ci int err; 98162306a36Sopenharmony_ci 98262306a36Sopenharmony_ci atmel_aes_set_mode(dd, rctx); 98362306a36Sopenharmony_ci 98462306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 98562306a36Sopenharmony_ci if (err) 98662306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 98762306a36Sopenharmony_ci 98862306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, use_dma, (void *)req->iv); 98962306a36Sopenharmony_ci if (use_dma) 99062306a36Sopenharmony_ci return atmel_aes_dma_start(dd, req->src, req->dst, 99162306a36Sopenharmony_ci req->cryptlen, 99262306a36Sopenharmony_ci atmel_aes_transfer_complete); 99362306a36Sopenharmony_ci 99462306a36Sopenharmony_ci return atmel_aes_cpu_start(dd, req->src, req->dst, req->cryptlen, 99562306a36Sopenharmony_ci atmel_aes_transfer_complete); 99662306a36Sopenharmony_ci} 99762306a36Sopenharmony_ci 99862306a36Sopenharmony_cistatic int atmel_aes_ctr_transfer(struct atmel_aes_dev *dd) 99962306a36Sopenharmony_ci{ 100062306a36Sopenharmony_ci struct atmel_aes_ctr_ctx *ctx = atmel_aes_ctr_ctx_cast(dd->ctx); 100162306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 100262306a36Sopenharmony_ci struct scatterlist *src, *dst; 100362306a36Sopenharmony_ci size_t datalen; 100462306a36Sopenharmony_ci u32 ctr; 100562306a36Sopenharmony_ci u16 start, end; 100662306a36Sopenharmony_ci bool use_dma, fragmented = false; 100762306a36Sopenharmony_ci 100862306a36Sopenharmony_ci /* Check for transfer completion. */ 100962306a36Sopenharmony_ci ctx->offset += dd->total; 101062306a36Sopenharmony_ci if (ctx->offset >= req->cryptlen) 101162306a36Sopenharmony_ci return atmel_aes_transfer_complete(dd); 101262306a36Sopenharmony_ci 101362306a36Sopenharmony_ci /* Compute data length. */ 101462306a36Sopenharmony_ci datalen = req->cryptlen - ctx->offset; 101562306a36Sopenharmony_ci ctx->blocks = DIV_ROUND_UP(datalen, AES_BLOCK_SIZE); 101662306a36Sopenharmony_ci ctr = be32_to_cpu(ctx->iv[3]); 101762306a36Sopenharmony_ci 101862306a36Sopenharmony_ci /* Check 16bit counter overflow. */ 101962306a36Sopenharmony_ci start = ctr & 0xffff; 102062306a36Sopenharmony_ci end = start + ctx->blocks - 1; 102162306a36Sopenharmony_ci 102262306a36Sopenharmony_ci if (ctx->blocks >> 16 || end < start) { 102362306a36Sopenharmony_ci ctr |= 0xffff; 102462306a36Sopenharmony_ci datalen = AES_BLOCK_SIZE * (0x10000 - start); 102562306a36Sopenharmony_ci fragmented = true; 102662306a36Sopenharmony_ci } 102762306a36Sopenharmony_ci 102862306a36Sopenharmony_ci use_dma = (datalen >= ATMEL_AES_DMA_THRESHOLD); 102962306a36Sopenharmony_ci 103062306a36Sopenharmony_ci /* Jump to offset. */ 103162306a36Sopenharmony_ci src = scatterwalk_ffwd(ctx->src, req->src, ctx->offset); 103262306a36Sopenharmony_ci dst = ((req->src == req->dst) ? src : 103362306a36Sopenharmony_ci scatterwalk_ffwd(ctx->dst, req->dst, ctx->offset)); 103462306a36Sopenharmony_ci 103562306a36Sopenharmony_ci /* Configure hardware. */ 103662306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, use_dma, ctx->iv); 103762306a36Sopenharmony_ci if (unlikely(fragmented)) { 103862306a36Sopenharmony_ci /* 103962306a36Sopenharmony_ci * Increment the counter manually to cope with the hardware 104062306a36Sopenharmony_ci * counter overflow. 104162306a36Sopenharmony_ci */ 104262306a36Sopenharmony_ci ctx->iv[3] = cpu_to_be32(ctr); 104362306a36Sopenharmony_ci crypto_inc((u8 *)ctx->iv, AES_BLOCK_SIZE); 104462306a36Sopenharmony_ci } 104562306a36Sopenharmony_ci 104662306a36Sopenharmony_ci if (use_dma) 104762306a36Sopenharmony_ci return atmel_aes_dma_start(dd, src, dst, datalen, 104862306a36Sopenharmony_ci atmel_aes_ctr_transfer); 104962306a36Sopenharmony_ci 105062306a36Sopenharmony_ci return atmel_aes_cpu_start(dd, src, dst, datalen, 105162306a36Sopenharmony_ci atmel_aes_ctr_transfer); 105262306a36Sopenharmony_ci} 105362306a36Sopenharmony_ci 105462306a36Sopenharmony_cistatic int atmel_aes_ctr_start(struct atmel_aes_dev *dd) 105562306a36Sopenharmony_ci{ 105662306a36Sopenharmony_ci struct atmel_aes_ctr_ctx *ctx = atmel_aes_ctr_ctx_cast(dd->ctx); 105762306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 105862306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 105962306a36Sopenharmony_ci int err; 106062306a36Sopenharmony_ci 106162306a36Sopenharmony_ci atmel_aes_set_mode(dd, rctx); 106262306a36Sopenharmony_ci 106362306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 106462306a36Sopenharmony_ci if (err) 106562306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 106662306a36Sopenharmony_ci 106762306a36Sopenharmony_ci memcpy(ctx->iv, req->iv, AES_BLOCK_SIZE); 106862306a36Sopenharmony_ci ctx->offset = 0; 106962306a36Sopenharmony_ci dd->total = 0; 107062306a36Sopenharmony_ci return atmel_aes_ctr_transfer(dd); 107162306a36Sopenharmony_ci} 107262306a36Sopenharmony_ci 107362306a36Sopenharmony_cistatic int atmel_aes_xts_fallback(struct skcipher_request *req, bool enc) 107462306a36Sopenharmony_ci{ 107562306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 107662306a36Sopenharmony_ci struct atmel_aes_xts_ctx *ctx = crypto_skcipher_ctx( 107762306a36Sopenharmony_ci crypto_skcipher_reqtfm(req)); 107862306a36Sopenharmony_ci 107962306a36Sopenharmony_ci skcipher_request_set_tfm(&rctx->fallback_req, ctx->fallback_tfm); 108062306a36Sopenharmony_ci skcipher_request_set_callback(&rctx->fallback_req, req->base.flags, 108162306a36Sopenharmony_ci req->base.complete, req->base.data); 108262306a36Sopenharmony_ci skcipher_request_set_crypt(&rctx->fallback_req, req->src, req->dst, 108362306a36Sopenharmony_ci req->cryptlen, req->iv); 108462306a36Sopenharmony_ci 108562306a36Sopenharmony_ci return enc ? crypto_skcipher_encrypt(&rctx->fallback_req) : 108662306a36Sopenharmony_ci crypto_skcipher_decrypt(&rctx->fallback_req); 108762306a36Sopenharmony_ci} 108862306a36Sopenharmony_ci 108962306a36Sopenharmony_cistatic int atmel_aes_crypt(struct skcipher_request *req, unsigned long mode) 109062306a36Sopenharmony_ci{ 109162306a36Sopenharmony_ci struct crypto_skcipher *skcipher = crypto_skcipher_reqtfm(req); 109262306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx = crypto_skcipher_ctx(skcipher); 109362306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx; 109462306a36Sopenharmony_ci u32 opmode = mode & AES_FLAGS_OPMODE_MASK; 109562306a36Sopenharmony_ci 109662306a36Sopenharmony_ci if (opmode == AES_FLAGS_XTS) { 109762306a36Sopenharmony_ci if (req->cryptlen < XTS_BLOCK_SIZE) 109862306a36Sopenharmony_ci return -EINVAL; 109962306a36Sopenharmony_ci 110062306a36Sopenharmony_ci if (!IS_ALIGNED(req->cryptlen, XTS_BLOCK_SIZE)) 110162306a36Sopenharmony_ci return atmel_aes_xts_fallback(req, 110262306a36Sopenharmony_ci mode & AES_FLAGS_ENCRYPT); 110362306a36Sopenharmony_ci } 110462306a36Sopenharmony_ci 110562306a36Sopenharmony_ci /* 110662306a36Sopenharmony_ci * ECB, CBC, CFB, OFB or CTR mode require the plaintext and ciphertext 110762306a36Sopenharmony_ci * to have a positve integer length. 110862306a36Sopenharmony_ci */ 110962306a36Sopenharmony_ci if (!req->cryptlen && opmode != AES_FLAGS_XTS) 111062306a36Sopenharmony_ci return 0; 111162306a36Sopenharmony_ci 111262306a36Sopenharmony_ci if ((opmode == AES_FLAGS_ECB || opmode == AES_FLAGS_CBC) && 111362306a36Sopenharmony_ci !IS_ALIGNED(req->cryptlen, crypto_skcipher_blocksize(skcipher))) 111462306a36Sopenharmony_ci return -EINVAL; 111562306a36Sopenharmony_ci 111662306a36Sopenharmony_ci switch (mode & AES_FLAGS_OPMODE_MASK) { 111762306a36Sopenharmony_ci case AES_FLAGS_CFB8: 111862306a36Sopenharmony_ci ctx->block_size = CFB8_BLOCK_SIZE; 111962306a36Sopenharmony_ci break; 112062306a36Sopenharmony_ci 112162306a36Sopenharmony_ci case AES_FLAGS_CFB16: 112262306a36Sopenharmony_ci ctx->block_size = CFB16_BLOCK_SIZE; 112362306a36Sopenharmony_ci break; 112462306a36Sopenharmony_ci 112562306a36Sopenharmony_ci case AES_FLAGS_CFB32: 112662306a36Sopenharmony_ci ctx->block_size = CFB32_BLOCK_SIZE; 112762306a36Sopenharmony_ci break; 112862306a36Sopenharmony_ci 112962306a36Sopenharmony_ci case AES_FLAGS_CFB64: 113062306a36Sopenharmony_ci ctx->block_size = CFB64_BLOCK_SIZE; 113162306a36Sopenharmony_ci break; 113262306a36Sopenharmony_ci 113362306a36Sopenharmony_ci default: 113462306a36Sopenharmony_ci ctx->block_size = AES_BLOCK_SIZE; 113562306a36Sopenharmony_ci break; 113662306a36Sopenharmony_ci } 113762306a36Sopenharmony_ci ctx->is_aead = false; 113862306a36Sopenharmony_ci 113962306a36Sopenharmony_ci rctx = skcipher_request_ctx(req); 114062306a36Sopenharmony_ci rctx->mode = mode; 114162306a36Sopenharmony_ci 114262306a36Sopenharmony_ci if (opmode != AES_FLAGS_ECB && 114362306a36Sopenharmony_ci !(mode & AES_FLAGS_ENCRYPT)) { 114462306a36Sopenharmony_ci unsigned int ivsize = crypto_skcipher_ivsize(skcipher); 114562306a36Sopenharmony_ci 114662306a36Sopenharmony_ci if (req->cryptlen >= ivsize) 114762306a36Sopenharmony_ci scatterwalk_map_and_copy(rctx->lastc, req->src, 114862306a36Sopenharmony_ci req->cryptlen - ivsize, 114962306a36Sopenharmony_ci ivsize, 0); 115062306a36Sopenharmony_ci } 115162306a36Sopenharmony_ci 115262306a36Sopenharmony_ci return atmel_aes_handle_queue(ctx->dd, &req->base); 115362306a36Sopenharmony_ci} 115462306a36Sopenharmony_ci 115562306a36Sopenharmony_cistatic int atmel_aes_setkey(struct crypto_skcipher *tfm, const u8 *key, 115662306a36Sopenharmony_ci unsigned int keylen) 115762306a36Sopenharmony_ci{ 115862306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx = crypto_skcipher_ctx(tfm); 115962306a36Sopenharmony_ci 116062306a36Sopenharmony_ci if (keylen != AES_KEYSIZE_128 && 116162306a36Sopenharmony_ci keylen != AES_KEYSIZE_192 && 116262306a36Sopenharmony_ci keylen != AES_KEYSIZE_256) 116362306a36Sopenharmony_ci return -EINVAL; 116462306a36Sopenharmony_ci 116562306a36Sopenharmony_ci memcpy(ctx->key, key, keylen); 116662306a36Sopenharmony_ci ctx->keylen = keylen; 116762306a36Sopenharmony_ci 116862306a36Sopenharmony_ci return 0; 116962306a36Sopenharmony_ci} 117062306a36Sopenharmony_ci 117162306a36Sopenharmony_cistatic int atmel_aes_ecb_encrypt(struct skcipher_request *req) 117262306a36Sopenharmony_ci{ 117362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_ECB | AES_FLAGS_ENCRYPT); 117462306a36Sopenharmony_ci} 117562306a36Sopenharmony_ci 117662306a36Sopenharmony_cistatic int atmel_aes_ecb_decrypt(struct skcipher_request *req) 117762306a36Sopenharmony_ci{ 117862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_ECB); 117962306a36Sopenharmony_ci} 118062306a36Sopenharmony_ci 118162306a36Sopenharmony_cistatic int atmel_aes_cbc_encrypt(struct skcipher_request *req) 118262306a36Sopenharmony_ci{ 118362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CBC | AES_FLAGS_ENCRYPT); 118462306a36Sopenharmony_ci} 118562306a36Sopenharmony_ci 118662306a36Sopenharmony_cistatic int atmel_aes_cbc_decrypt(struct skcipher_request *req) 118762306a36Sopenharmony_ci{ 118862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CBC); 118962306a36Sopenharmony_ci} 119062306a36Sopenharmony_ci 119162306a36Sopenharmony_cistatic int atmel_aes_ofb_encrypt(struct skcipher_request *req) 119262306a36Sopenharmony_ci{ 119362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_OFB | AES_FLAGS_ENCRYPT); 119462306a36Sopenharmony_ci} 119562306a36Sopenharmony_ci 119662306a36Sopenharmony_cistatic int atmel_aes_ofb_decrypt(struct skcipher_request *req) 119762306a36Sopenharmony_ci{ 119862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_OFB); 119962306a36Sopenharmony_ci} 120062306a36Sopenharmony_ci 120162306a36Sopenharmony_cistatic int atmel_aes_cfb_encrypt(struct skcipher_request *req) 120262306a36Sopenharmony_ci{ 120362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB128 | AES_FLAGS_ENCRYPT); 120462306a36Sopenharmony_ci} 120562306a36Sopenharmony_ci 120662306a36Sopenharmony_cistatic int atmel_aes_cfb_decrypt(struct skcipher_request *req) 120762306a36Sopenharmony_ci{ 120862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB128); 120962306a36Sopenharmony_ci} 121062306a36Sopenharmony_ci 121162306a36Sopenharmony_cistatic int atmel_aes_cfb64_encrypt(struct skcipher_request *req) 121262306a36Sopenharmony_ci{ 121362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB64 | AES_FLAGS_ENCRYPT); 121462306a36Sopenharmony_ci} 121562306a36Sopenharmony_ci 121662306a36Sopenharmony_cistatic int atmel_aes_cfb64_decrypt(struct skcipher_request *req) 121762306a36Sopenharmony_ci{ 121862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB64); 121962306a36Sopenharmony_ci} 122062306a36Sopenharmony_ci 122162306a36Sopenharmony_cistatic int atmel_aes_cfb32_encrypt(struct skcipher_request *req) 122262306a36Sopenharmony_ci{ 122362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB32 | AES_FLAGS_ENCRYPT); 122462306a36Sopenharmony_ci} 122562306a36Sopenharmony_ci 122662306a36Sopenharmony_cistatic int atmel_aes_cfb32_decrypt(struct skcipher_request *req) 122762306a36Sopenharmony_ci{ 122862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB32); 122962306a36Sopenharmony_ci} 123062306a36Sopenharmony_ci 123162306a36Sopenharmony_cistatic int atmel_aes_cfb16_encrypt(struct skcipher_request *req) 123262306a36Sopenharmony_ci{ 123362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB16 | AES_FLAGS_ENCRYPT); 123462306a36Sopenharmony_ci} 123562306a36Sopenharmony_ci 123662306a36Sopenharmony_cistatic int atmel_aes_cfb16_decrypt(struct skcipher_request *req) 123762306a36Sopenharmony_ci{ 123862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB16); 123962306a36Sopenharmony_ci} 124062306a36Sopenharmony_ci 124162306a36Sopenharmony_cistatic int atmel_aes_cfb8_encrypt(struct skcipher_request *req) 124262306a36Sopenharmony_ci{ 124362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB8 | AES_FLAGS_ENCRYPT); 124462306a36Sopenharmony_ci} 124562306a36Sopenharmony_ci 124662306a36Sopenharmony_cistatic int atmel_aes_cfb8_decrypt(struct skcipher_request *req) 124762306a36Sopenharmony_ci{ 124862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CFB8); 124962306a36Sopenharmony_ci} 125062306a36Sopenharmony_ci 125162306a36Sopenharmony_cistatic int atmel_aes_ctr_encrypt(struct skcipher_request *req) 125262306a36Sopenharmony_ci{ 125362306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CTR | AES_FLAGS_ENCRYPT); 125462306a36Sopenharmony_ci} 125562306a36Sopenharmony_ci 125662306a36Sopenharmony_cistatic int atmel_aes_ctr_decrypt(struct skcipher_request *req) 125762306a36Sopenharmony_ci{ 125862306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_CTR); 125962306a36Sopenharmony_ci} 126062306a36Sopenharmony_ci 126162306a36Sopenharmony_cistatic int atmel_aes_init_tfm(struct crypto_skcipher *tfm) 126262306a36Sopenharmony_ci{ 126362306a36Sopenharmony_ci struct atmel_aes_ctx *ctx = crypto_skcipher_ctx(tfm); 126462306a36Sopenharmony_ci struct atmel_aes_dev *dd; 126562306a36Sopenharmony_ci 126662306a36Sopenharmony_ci dd = atmel_aes_dev_alloc(&ctx->base); 126762306a36Sopenharmony_ci if (!dd) 126862306a36Sopenharmony_ci return -ENODEV; 126962306a36Sopenharmony_ci 127062306a36Sopenharmony_ci crypto_skcipher_set_reqsize(tfm, sizeof(struct atmel_aes_reqctx)); 127162306a36Sopenharmony_ci ctx->base.dd = dd; 127262306a36Sopenharmony_ci ctx->base.start = atmel_aes_start; 127362306a36Sopenharmony_ci 127462306a36Sopenharmony_ci return 0; 127562306a36Sopenharmony_ci} 127662306a36Sopenharmony_ci 127762306a36Sopenharmony_cistatic int atmel_aes_ctr_init_tfm(struct crypto_skcipher *tfm) 127862306a36Sopenharmony_ci{ 127962306a36Sopenharmony_ci struct atmel_aes_ctx *ctx = crypto_skcipher_ctx(tfm); 128062306a36Sopenharmony_ci struct atmel_aes_dev *dd; 128162306a36Sopenharmony_ci 128262306a36Sopenharmony_ci dd = atmel_aes_dev_alloc(&ctx->base); 128362306a36Sopenharmony_ci if (!dd) 128462306a36Sopenharmony_ci return -ENODEV; 128562306a36Sopenharmony_ci 128662306a36Sopenharmony_ci crypto_skcipher_set_reqsize(tfm, sizeof(struct atmel_aes_reqctx)); 128762306a36Sopenharmony_ci ctx->base.dd = dd; 128862306a36Sopenharmony_ci ctx->base.start = atmel_aes_ctr_start; 128962306a36Sopenharmony_ci 129062306a36Sopenharmony_ci return 0; 129162306a36Sopenharmony_ci} 129262306a36Sopenharmony_ci 129362306a36Sopenharmony_cistatic struct skcipher_alg aes_algs[] = { 129462306a36Sopenharmony_ci{ 129562306a36Sopenharmony_ci .base.cra_name = "ecb(aes)", 129662306a36Sopenharmony_ci .base.cra_driver_name = "atmel-ecb-aes", 129762306a36Sopenharmony_ci .base.cra_blocksize = AES_BLOCK_SIZE, 129862306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 129962306a36Sopenharmony_ci 130062306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 130162306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 130262306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 130362306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 130462306a36Sopenharmony_ci .encrypt = atmel_aes_ecb_encrypt, 130562306a36Sopenharmony_ci .decrypt = atmel_aes_ecb_decrypt, 130662306a36Sopenharmony_ci}, 130762306a36Sopenharmony_ci{ 130862306a36Sopenharmony_ci .base.cra_name = "cbc(aes)", 130962306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cbc-aes", 131062306a36Sopenharmony_ci .base.cra_blocksize = AES_BLOCK_SIZE, 131162306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 131262306a36Sopenharmony_ci 131362306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 131462306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 131562306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 131662306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 131762306a36Sopenharmony_ci .encrypt = atmel_aes_cbc_encrypt, 131862306a36Sopenharmony_ci .decrypt = atmel_aes_cbc_decrypt, 131962306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 132062306a36Sopenharmony_ci}, 132162306a36Sopenharmony_ci{ 132262306a36Sopenharmony_ci .base.cra_name = "ofb(aes)", 132362306a36Sopenharmony_ci .base.cra_driver_name = "atmel-ofb-aes", 132462306a36Sopenharmony_ci .base.cra_blocksize = 1, 132562306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 132662306a36Sopenharmony_ci 132762306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 132862306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 132962306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 133062306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 133162306a36Sopenharmony_ci .encrypt = atmel_aes_ofb_encrypt, 133262306a36Sopenharmony_ci .decrypt = atmel_aes_ofb_decrypt, 133362306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 133462306a36Sopenharmony_ci}, 133562306a36Sopenharmony_ci{ 133662306a36Sopenharmony_ci .base.cra_name = "cfb(aes)", 133762306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cfb-aes", 133862306a36Sopenharmony_ci .base.cra_blocksize = 1, 133962306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 134062306a36Sopenharmony_ci 134162306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 134262306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 134362306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 134462306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 134562306a36Sopenharmony_ci .encrypt = atmel_aes_cfb_encrypt, 134662306a36Sopenharmony_ci .decrypt = atmel_aes_cfb_decrypt, 134762306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 134862306a36Sopenharmony_ci}, 134962306a36Sopenharmony_ci{ 135062306a36Sopenharmony_ci .base.cra_name = "cfb32(aes)", 135162306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cfb32-aes", 135262306a36Sopenharmony_ci .base.cra_blocksize = CFB32_BLOCK_SIZE, 135362306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 135462306a36Sopenharmony_ci 135562306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 135662306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 135762306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 135862306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 135962306a36Sopenharmony_ci .encrypt = atmel_aes_cfb32_encrypt, 136062306a36Sopenharmony_ci .decrypt = atmel_aes_cfb32_decrypt, 136162306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 136262306a36Sopenharmony_ci}, 136362306a36Sopenharmony_ci{ 136462306a36Sopenharmony_ci .base.cra_name = "cfb16(aes)", 136562306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cfb16-aes", 136662306a36Sopenharmony_ci .base.cra_blocksize = CFB16_BLOCK_SIZE, 136762306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 136862306a36Sopenharmony_ci 136962306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 137062306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 137162306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 137262306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 137362306a36Sopenharmony_ci .encrypt = atmel_aes_cfb16_encrypt, 137462306a36Sopenharmony_ci .decrypt = atmel_aes_cfb16_decrypt, 137562306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 137662306a36Sopenharmony_ci}, 137762306a36Sopenharmony_ci{ 137862306a36Sopenharmony_ci .base.cra_name = "cfb8(aes)", 137962306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cfb8-aes", 138062306a36Sopenharmony_ci .base.cra_blocksize = CFB8_BLOCK_SIZE, 138162306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 138262306a36Sopenharmony_ci 138362306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 138462306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 138562306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 138662306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 138762306a36Sopenharmony_ci .encrypt = atmel_aes_cfb8_encrypt, 138862306a36Sopenharmony_ci .decrypt = atmel_aes_cfb8_decrypt, 138962306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 139062306a36Sopenharmony_ci}, 139162306a36Sopenharmony_ci{ 139262306a36Sopenharmony_ci .base.cra_name = "ctr(aes)", 139362306a36Sopenharmony_ci .base.cra_driver_name = "atmel-ctr-aes", 139462306a36Sopenharmony_ci .base.cra_blocksize = 1, 139562306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctr_ctx), 139662306a36Sopenharmony_ci 139762306a36Sopenharmony_ci .init = atmel_aes_ctr_init_tfm, 139862306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 139962306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 140062306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 140162306a36Sopenharmony_ci .encrypt = atmel_aes_ctr_encrypt, 140262306a36Sopenharmony_ci .decrypt = atmel_aes_ctr_decrypt, 140362306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 140462306a36Sopenharmony_ci}, 140562306a36Sopenharmony_ci}; 140662306a36Sopenharmony_ci 140762306a36Sopenharmony_cistatic struct skcipher_alg aes_cfb64_alg = { 140862306a36Sopenharmony_ci .base.cra_name = "cfb64(aes)", 140962306a36Sopenharmony_ci .base.cra_driver_name = "atmel-cfb64-aes", 141062306a36Sopenharmony_ci .base.cra_blocksize = CFB64_BLOCK_SIZE, 141162306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_ctx), 141262306a36Sopenharmony_ci 141362306a36Sopenharmony_ci .init = atmel_aes_init_tfm, 141462306a36Sopenharmony_ci .min_keysize = AES_MIN_KEY_SIZE, 141562306a36Sopenharmony_ci .max_keysize = AES_MAX_KEY_SIZE, 141662306a36Sopenharmony_ci .setkey = atmel_aes_setkey, 141762306a36Sopenharmony_ci .encrypt = atmel_aes_cfb64_encrypt, 141862306a36Sopenharmony_ci .decrypt = atmel_aes_cfb64_decrypt, 141962306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 142062306a36Sopenharmony_ci}; 142162306a36Sopenharmony_ci 142262306a36Sopenharmony_ci 142362306a36Sopenharmony_ci/* gcm aead functions */ 142462306a36Sopenharmony_ci 142562306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash(struct atmel_aes_dev *dd, 142662306a36Sopenharmony_ci const u32 *data, size_t datalen, 142762306a36Sopenharmony_ci const __be32 *ghash_in, __be32 *ghash_out, 142862306a36Sopenharmony_ci atmel_aes_fn_t resume); 142962306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash_init(struct atmel_aes_dev *dd); 143062306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash_finalize(struct atmel_aes_dev *dd); 143162306a36Sopenharmony_ci 143262306a36Sopenharmony_cistatic int atmel_aes_gcm_start(struct atmel_aes_dev *dd); 143362306a36Sopenharmony_cistatic int atmel_aes_gcm_process(struct atmel_aes_dev *dd); 143462306a36Sopenharmony_cistatic int atmel_aes_gcm_length(struct atmel_aes_dev *dd); 143562306a36Sopenharmony_cistatic int atmel_aes_gcm_data(struct atmel_aes_dev *dd); 143662306a36Sopenharmony_cistatic int atmel_aes_gcm_tag_init(struct atmel_aes_dev *dd); 143762306a36Sopenharmony_cistatic int atmel_aes_gcm_tag(struct atmel_aes_dev *dd); 143862306a36Sopenharmony_cistatic int atmel_aes_gcm_finalize(struct atmel_aes_dev *dd); 143962306a36Sopenharmony_ci 144062306a36Sopenharmony_cistatic inline struct atmel_aes_gcm_ctx * 144162306a36Sopenharmony_ciatmel_aes_gcm_ctx_cast(struct atmel_aes_base_ctx *ctx) 144262306a36Sopenharmony_ci{ 144362306a36Sopenharmony_ci return container_of(ctx, struct atmel_aes_gcm_ctx, base); 144462306a36Sopenharmony_ci} 144562306a36Sopenharmony_ci 144662306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash(struct atmel_aes_dev *dd, 144762306a36Sopenharmony_ci const u32 *data, size_t datalen, 144862306a36Sopenharmony_ci const __be32 *ghash_in, __be32 *ghash_out, 144962306a36Sopenharmony_ci atmel_aes_fn_t resume) 145062306a36Sopenharmony_ci{ 145162306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 145262306a36Sopenharmony_ci 145362306a36Sopenharmony_ci dd->data = (u32 *)data; 145462306a36Sopenharmony_ci dd->datalen = datalen; 145562306a36Sopenharmony_ci ctx->ghash_in = ghash_in; 145662306a36Sopenharmony_ci ctx->ghash_out = ghash_out; 145762306a36Sopenharmony_ci ctx->ghash_resume = resume; 145862306a36Sopenharmony_ci 145962306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, false, NULL); 146062306a36Sopenharmony_ci return atmel_aes_wait_for_data_ready(dd, atmel_aes_gcm_ghash_init); 146162306a36Sopenharmony_ci} 146262306a36Sopenharmony_ci 146362306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash_init(struct atmel_aes_dev *dd) 146462306a36Sopenharmony_ci{ 146562306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 146662306a36Sopenharmony_ci 146762306a36Sopenharmony_ci /* Set the data length. */ 146862306a36Sopenharmony_ci atmel_aes_write(dd, AES_AADLENR, dd->total); 146962306a36Sopenharmony_ci atmel_aes_write(dd, AES_CLENR, 0); 147062306a36Sopenharmony_ci 147162306a36Sopenharmony_ci /* If needed, overwrite the GCM Intermediate Hash Word Registers */ 147262306a36Sopenharmony_ci if (ctx->ghash_in) 147362306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_GHASHR(0), ctx->ghash_in); 147462306a36Sopenharmony_ci 147562306a36Sopenharmony_ci return atmel_aes_gcm_ghash_finalize(dd); 147662306a36Sopenharmony_ci} 147762306a36Sopenharmony_ci 147862306a36Sopenharmony_cistatic int atmel_aes_gcm_ghash_finalize(struct atmel_aes_dev *dd) 147962306a36Sopenharmony_ci{ 148062306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 148162306a36Sopenharmony_ci u32 isr; 148262306a36Sopenharmony_ci 148362306a36Sopenharmony_ci /* Write data into the Input Data Registers. */ 148462306a36Sopenharmony_ci while (dd->datalen > 0) { 148562306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), dd->data); 148662306a36Sopenharmony_ci dd->data += 4; 148762306a36Sopenharmony_ci dd->datalen -= AES_BLOCK_SIZE; 148862306a36Sopenharmony_ci 148962306a36Sopenharmony_ci isr = atmel_aes_read(dd, AES_ISR); 149062306a36Sopenharmony_ci if (!(isr & AES_INT_DATARDY)) { 149162306a36Sopenharmony_ci dd->resume = atmel_aes_gcm_ghash_finalize; 149262306a36Sopenharmony_ci atmel_aes_write(dd, AES_IER, AES_INT_DATARDY); 149362306a36Sopenharmony_ci return -EINPROGRESS; 149462306a36Sopenharmony_ci } 149562306a36Sopenharmony_ci } 149662306a36Sopenharmony_ci 149762306a36Sopenharmony_ci /* Read the computed hash from GHASHRx. */ 149862306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_GHASHR(0), ctx->ghash_out); 149962306a36Sopenharmony_ci 150062306a36Sopenharmony_ci return ctx->ghash_resume(dd); 150162306a36Sopenharmony_ci} 150262306a36Sopenharmony_ci 150362306a36Sopenharmony_ci 150462306a36Sopenharmony_cistatic int atmel_aes_gcm_start(struct atmel_aes_dev *dd) 150562306a36Sopenharmony_ci{ 150662306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 150762306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 150862306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 150962306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = aead_request_ctx(req); 151062306a36Sopenharmony_ci size_t ivsize = crypto_aead_ivsize(tfm); 151162306a36Sopenharmony_ci size_t datalen, padlen; 151262306a36Sopenharmony_ci const void *iv = req->iv; 151362306a36Sopenharmony_ci u8 *data = dd->buf; 151462306a36Sopenharmony_ci int err; 151562306a36Sopenharmony_ci 151662306a36Sopenharmony_ci atmel_aes_set_mode(dd, rctx); 151762306a36Sopenharmony_ci 151862306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 151962306a36Sopenharmony_ci if (err) 152062306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 152162306a36Sopenharmony_ci 152262306a36Sopenharmony_ci if (likely(ivsize == GCM_AES_IV_SIZE)) { 152362306a36Sopenharmony_ci memcpy(ctx->j0, iv, ivsize); 152462306a36Sopenharmony_ci ctx->j0[3] = cpu_to_be32(1); 152562306a36Sopenharmony_ci return atmel_aes_gcm_process(dd); 152662306a36Sopenharmony_ci } 152762306a36Sopenharmony_ci 152862306a36Sopenharmony_ci padlen = atmel_aes_padlen(ivsize, AES_BLOCK_SIZE); 152962306a36Sopenharmony_ci datalen = ivsize + padlen + AES_BLOCK_SIZE; 153062306a36Sopenharmony_ci if (datalen > dd->buflen) 153162306a36Sopenharmony_ci return atmel_aes_complete(dd, -EINVAL); 153262306a36Sopenharmony_ci 153362306a36Sopenharmony_ci memcpy(data, iv, ivsize); 153462306a36Sopenharmony_ci memset(data + ivsize, 0, padlen + sizeof(u64)); 153562306a36Sopenharmony_ci ((__be64 *)(data + datalen))[-1] = cpu_to_be64(ivsize * 8); 153662306a36Sopenharmony_ci 153762306a36Sopenharmony_ci return atmel_aes_gcm_ghash(dd, (const u32 *)data, datalen, 153862306a36Sopenharmony_ci NULL, ctx->j0, atmel_aes_gcm_process); 153962306a36Sopenharmony_ci} 154062306a36Sopenharmony_ci 154162306a36Sopenharmony_cistatic int atmel_aes_gcm_process(struct atmel_aes_dev *dd) 154262306a36Sopenharmony_ci{ 154362306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 154462306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 154562306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 154662306a36Sopenharmony_ci bool enc = atmel_aes_is_encrypt(dd); 154762306a36Sopenharmony_ci u32 authsize; 154862306a36Sopenharmony_ci 154962306a36Sopenharmony_ci /* Compute text length. */ 155062306a36Sopenharmony_ci authsize = crypto_aead_authsize(tfm); 155162306a36Sopenharmony_ci ctx->textlen = req->cryptlen - (enc ? 0 : authsize); 155262306a36Sopenharmony_ci 155362306a36Sopenharmony_ci /* 155462306a36Sopenharmony_ci * According to tcrypt test suite, the GCM Automatic Tag Generation 155562306a36Sopenharmony_ci * fails when both the message and its associated data are empty. 155662306a36Sopenharmony_ci */ 155762306a36Sopenharmony_ci if (likely(req->assoclen != 0 || ctx->textlen != 0)) 155862306a36Sopenharmony_ci dd->flags |= AES_FLAGS_GTAGEN; 155962306a36Sopenharmony_ci 156062306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, false, NULL); 156162306a36Sopenharmony_ci return atmel_aes_wait_for_data_ready(dd, atmel_aes_gcm_length); 156262306a36Sopenharmony_ci} 156362306a36Sopenharmony_ci 156462306a36Sopenharmony_cistatic int atmel_aes_gcm_length(struct atmel_aes_dev *dd) 156562306a36Sopenharmony_ci{ 156662306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 156762306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 156862306a36Sopenharmony_ci __be32 j0_lsw, *j0 = ctx->j0; 156962306a36Sopenharmony_ci size_t padlen; 157062306a36Sopenharmony_ci 157162306a36Sopenharmony_ci /* Write incr32(J0) into IV. */ 157262306a36Sopenharmony_ci j0_lsw = j0[3]; 157362306a36Sopenharmony_ci be32_add_cpu(&j0[3], 1); 157462306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IVR(0), j0); 157562306a36Sopenharmony_ci j0[3] = j0_lsw; 157662306a36Sopenharmony_ci 157762306a36Sopenharmony_ci /* Set aad and text lengths. */ 157862306a36Sopenharmony_ci atmel_aes_write(dd, AES_AADLENR, req->assoclen); 157962306a36Sopenharmony_ci atmel_aes_write(dd, AES_CLENR, ctx->textlen); 158062306a36Sopenharmony_ci 158162306a36Sopenharmony_ci /* Check whether AAD are present. */ 158262306a36Sopenharmony_ci if (unlikely(req->assoclen == 0)) { 158362306a36Sopenharmony_ci dd->datalen = 0; 158462306a36Sopenharmony_ci return atmel_aes_gcm_data(dd); 158562306a36Sopenharmony_ci } 158662306a36Sopenharmony_ci 158762306a36Sopenharmony_ci /* Copy assoc data and add padding. */ 158862306a36Sopenharmony_ci padlen = atmel_aes_padlen(req->assoclen, AES_BLOCK_SIZE); 158962306a36Sopenharmony_ci if (unlikely(req->assoclen + padlen > dd->buflen)) 159062306a36Sopenharmony_ci return atmel_aes_complete(dd, -EINVAL); 159162306a36Sopenharmony_ci sg_copy_to_buffer(req->src, sg_nents(req->src), dd->buf, req->assoclen); 159262306a36Sopenharmony_ci 159362306a36Sopenharmony_ci /* Write assoc data into the Input Data register. */ 159462306a36Sopenharmony_ci dd->data = (u32 *)dd->buf; 159562306a36Sopenharmony_ci dd->datalen = req->assoclen + padlen; 159662306a36Sopenharmony_ci return atmel_aes_gcm_data(dd); 159762306a36Sopenharmony_ci} 159862306a36Sopenharmony_ci 159962306a36Sopenharmony_cistatic int atmel_aes_gcm_data(struct atmel_aes_dev *dd) 160062306a36Sopenharmony_ci{ 160162306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 160262306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 160362306a36Sopenharmony_ci bool use_dma = (ctx->textlen >= ATMEL_AES_DMA_THRESHOLD); 160462306a36Sopenharmony_ci struct scatterlist *src, *dst; 160562306a36Sopenharmony_ci u32 isr, mr; 160662306a36Sopenharmony_ci 160762306a36Sopenharmony_ci /* Write AAD first. */ 160862306a36Sopenharmony_ci while (dd->datalen > 0) { 160962306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), dd->data); 161062306a36Sopenharmony_ci dd->data += 4; 161162306a36Sopenharmony_ci dd->datalen -= AES_BLOCK_SIZE; 161262306a36Sopenharmony_ci 161362306a36Sopenharmony_ci isr = atmel_aes_read(dd, AES_ISR); 161462306a36Sopenharmony_ci if (!(isr & AES_INT_DATARDY)) { 161562306a36Sopenharmony_ci dd->resume = atmel_aes_gcm_data; 161662306a36Sopenharmony_ci atmel_aes_write(dd, AES_IER, AES_INT_DATARDY); 161762306a36Sopenharmony_ci return -EINPROGRESS; 161862306a36Sopenharmony_ci } 161962306a36Sopenharmony_ci } 162062306a36Sopenharmony_ci 162162306a36Sopenharmony_ci /* GMAC only. */ 162262306a36Sopenharmony_ci if (unlikely(ctx->textlen == 0)) 162362306a36Sopenharmony_ci return atmel_aes_gcm_tag_init(dd); 162462306a36Sopenharmony_ci 162562306a36Sopenharmony_ci /* Prepare src and dst scatter lists to transfer cipher/plain texts */ 162662306a36Sopenharmony_ci src = scatterwalk_ffwd(ctx->src, req->src, req->assoclen); 162762306a36Sopenharmony_ci dst = ((req->src == req->dst) ? src : 162862306a36Sopenharmony_ci scatterwalk_ffwd(ctx->dst, req->dst, req->assoclen)); 162962306a36Sopenharmony_ci 163062306a36Sopenharmony_ci if (use_dma) { 163162306a36Sopenharmony_ci /* Update the Mode Register for DMA transfers. */ 163262306a36Sopenharmony_ci mr = atmel_aes_read(dd, AES_MR); 163362306a36Sopenharmony_ci mr &= ~(AES_MR_SMOD_MASK | AES_MR_DUALBUFF); 163462306a36Sopenharmony_ci mr |= AES_MR_SMOD_IDATAR0; 163562306a36Sopenharmony_ci if (dd->caps.has_dualbuff) 163662306a36Sopenharmony_ci mr |= AES_MR_DUALBUFF; 163762306a36Sopenharmony_ci atmel_aes_write(dd, AES_MR, mr); 163862306a36Sopenharmony_ci 163962306a36Sopenharmony_ci return atmel_aes_dma_start(dd, src, dst, ctx->textlen, 164062306a36Sopenharmony_ci atmel_aes_gcm_tag_init); 164162306a36Sopenharmony_ci } 164262306a36Sopenharmony_ci 164362306a36Sopenharmony_ci return atmel_aes_cpu_start(dd, src, dst, ctx->textlen, 164462306a36Sopenharmony_ci atmel_aes_gcm_tag_init); 164562306a36Sopenharmony_ci} 164662306a36Sopenharmony_ci 164762306a36Sopenharmony_cistatic int atmel_aes_gcm_tag_init(struct atmel_aes_dev *dd) 164862306a36Sopenharmony_ci{ 164962306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 165062306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 165162306a36Sopenharmony_ci __be64 *data = dd->buf; 165262306a36Sopenharmony_ci 165362306a36Sopenharmony_ci if (likely(dd->flags & AES_FLAGS_GTAGEN)) { 165462306a36Sopenharmony_ci if (!(atmel_aes_read(dd, AES_ISR) & AES_INT_TAGRDY)) { 165562306a36Sopenharmony_ci dd->resume = atmel_aes_gcm_tag_init; 165662306a36Sopenharmony_ci atmel_aes_write(dd, AES_IER, AES_INT_TAGRDY); 165762306a36Sopenharmony_ci return -EINPROGRESS; 165862306a36Sopenharmony_ci } 165962306a36Sopenharmony_ci 166062306a36Sopenharmony_ci return atmel_aes_gcm_finalize(dd); 166162306a36Sopenharmony_ci } 166262306a36Sopenharmony_ci 166362306a36Sopenharmony_ci /* Read the GCM Intermediate Hash Word Registers. */ 166462306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_GHASHR(0), ctx->ghash); 166562306a36Sopenharmony_ci 166662306a36Sopenharmony_ci data[0] = cpu_to_be64(req->assoclen * 8); 166762306a36Sopenharmony_ci data[1] = cpu_to_be64(ctx->textlen * 8); 166862306a36Sopenharmony_ci 166962306a36Sopenharmony_ci return atmel_aes_gcm_ghash(dd, (const u32 *)data, AES_BLOCK_SIZE, 167062306a36Sopenharmony_ci ctx->ghash, ctx->ghash, atmel_aes_gcm_tag); 167162306a36Sopenharmony_ci} 167262306a36Sopenharmony_ci 167362306a36Sopenharmony_cistatic int atmel_aes_gcm_tag(struct atmel_aes_dev *dd) 167462306a36Sopenharmony_ci{ 167562306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 167662306a36Sopenharmony_ci unsigned long flags; 167762306a36Sopenharmony_ci 167862306a36Sopenharmony_ci /* 167962306a36Sopenharmony_ci * Change mode to CTR to complete the tag generation. 168062306a36Sopenharmony_ci * Use J0 as Initialization Vector. 168162306a36Sopenharmony_ci */ 168262306a36Sopenharmony_ci flags = dd->flags; 168362306a36Sopenharmony_ci dd->flags &= ~(AES_FLAGS_OPMODE_MASK | AES_FLAGS_GTAGEN); 168462306a36Sopenharmony_ci dd->flags |= AES_FLAGS_CTR; 168562306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, false, ctx->j0); 168662306a36Sopenharmony_ci dd->flags = flags; 168762306a36Sopenharmony_ci 168862306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), ctx->ghash); 168962306a36Sopenharmony_ci return atmel_aes_wait_for_data_ready(dd, atmel_aes_gcm_finalize); 169062306a36Sopenharmony_ci} 169162306a36Sopenharmony_ci 169262306a36Sopenharmony_cistatic int atmel_aes_gcm_finalize(struct atmel_aes_dev *dd) 169362306a36Sopenharmony_ci{ 169462306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = atmel_aes_gcm_ctx_cast(dd->ctx); 169562306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 169662306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 169762306a36Sopenharmony_ci bool enc = atmel_aes_is_encrypt(dd); 169862306a36Sopenharmony_ci u32 offset, authsize, itag[4], *otag = ctx->tag; 169962306a36Sopenharmony_ci int err; 170062306a36Sopenharmony_ci 170162306a36Sopenharmony_ci /* Read the computed tag. */ 170262306a36Sopenharmony_ci if (likely(dd->flags & AES_FLAGS_GTAGEN)) 170362306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_TAGR(0), ctx->tag); 170462306a36Sopenharmony_ci else 170562306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_ODATAR(0), ctx->tag); 170662306a36Sopenharmony_ci 170762306a36Sopenharmony_ci offset = req->assoclen + ctx->textlen; 170862306a36Sopenharmony_ci authsize = crypto_aead_authsize(tfm); 170962306a36Sopenharmony_ci if (enc) { 171062306a36Sopenharmony_ci scatterwalk_map_and_copy(otag, req->dst, offset, authsize, 1); 171162306a36Sopenharmony_ci err = 0; 171262306a36Sopenharmony_ci } else { 171362306a36Sopenharmony_ci scatterwalk_map_and_copy(itag, req->src, offset, authsize, 0); 171462306a36Sopenharmony_ci err = crypto_memneq(itag, otag, authsize) ? -EBADMSG : 0; 171562306a36Sopenharmony_ci } 171662306a36Sopenharmony_ci 171762306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 171862306a36Sopenharmony_ci} 171962306a36Sopenharmony_ci 172062306a36Sopenharmony_cistatic int atmel_aes_gcm_crypt(struct aead_request *req, 172162306a36Sopenharmony_ci unsigned long mode) 172262306a36Sopenharmony_ci{ 172362306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx; 172462306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx; 172562306a36Sopenharmony_ci 172662306a36Sopenharmony_ci ctx = crypto_aead_ctx(crypto_aead_reqtfm(req)); 172762306a36Sopenharmony_ci ctx->block_size = AES_BLOCK_SIZE; 172862306a36Sopenharmony_ci ctx->is_aead = true; 172962306a36Sopenharmony_ci 173062306a36Sopenharmony_ci rctx = aead_request_ctx(req); 173162306a36Sopenharmony_ci rctx->mode = AES_FLAGS_GCM | mode; 173262306a36Sopenharmony_ci 173362306a36Sopenharmony_ci return atmel_aes_handle_queue(ctx->dd, &req->base); 173462306a36Sopenharmony_ci} 173562306a36Sopenharmony_ci 173662306a36Sopenharmony_cistatic int atmel_aes_gcm_setkey(struct crypto_aead *tfm, const u8 *key, 173762306a36Sopenharmony_ci unsigned int keylen) 173862306a36Sopenharmony_ci{ 173962306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx = crypto_aead_ctx(tfm); 174062306a36Sopenharmony_ci 174162306a36Sopenharmony_ci if (keylen != AES_KEYSIZE_256 && 174262306a36Sopenharmony_ci keylen != AES_KEYSIZE_192 && 174362306a36Sopenharmony_ci keylen != AES_KEYSIZE_128) 174462306a36Sopenharmony_ci return -EINVAL; 174562306a36Sopenharmony_ci 174662306a36Sopenharmony_ci memcpy(ctx->key, key, keylen); 174762306a36Sopenharmony_ci ctx->keylen = keylen; 174862306a36Sopenharmony_ci 174962306a36Sopenharmony_ci return 0; 175062306a36Sopenharmony_ci} 175162306a36Sopenharmony_ci 175262306a36Sopenharmony_cistatic int atmel_aes_gcm_setauthsize(struct crypto_aead *tfm, 175362306a36Sopenharmony_ci unsigned int authsize) 175462306a36Sopenharmony_ci{ 175562306a36Sopenharmony_ci return crypto_gcm_check_authsize(authsize); 175662306a36Sopenharmony_ci} 175762306a36Sopenharmony_ci 175862306a36Sopenharmony_cistatic int atmel_aes_gcm_encrypt(struct aead_request *req) 175962306a36Sopenharmony_ci{ 176062306a36Sopenharmony_ci return atmel_aes_gcm_crypt(req, AES_FLAGS_ENCRYPT); 176162306a36Sopenharmony_ci} 176262306a36Sopenharmony_ci 176362306a36Sopenharmony_cistatic int atmel_aes_gcm_decrypt(struct aead_request *req) 176462306a36Sopenharmony_ci{ 176562306a36Sopenharmony_ci return atmel_aes_gcm_crypt(req, 0); 176662306a36Sopenharmony_ci} 176762306a36Sopenharmony_ci 176862306a36Sopenharmony_cistatic int atmel_aes_gcm_init(struct crypto_aead *tfm) 176962306a36Sopenharmony_ci{ 177062306a36Sopenharmony_ci struct atmel_aes_gcm_ctx *ctx = crypto_aead_ctx(tfm); 177162306a36Sopenharmony_ci struct atmel_aes_dev *dd; 177262306a36Sopenharmony_ci 177362306a36Sopenharmony_ci dd = atmel_aes_dev_alloc(&ctx->base); 177462306a36Sopenharmony_ci if (!dd) 177562306a36Sopenharmony_ci return -ENODEV; 177662306a36Sopenharmony_ci 177762306a36Sopenharmony_ci crypto_aead_set_reqsize(tfm, sizeof(struct atmel_aes_reqctx)); 177862306a36Sopenharmony_ci ctx->base.dd = dd; 177962306a36Sopenharmony_ci ctx->base.start = atmel_aes_gcm_start; 178062306a36Sopenharmony_ci 178162306a36Sopenharmony_ci return 0; 178262306a36Sopenharmony_ci} 178362306a36Sopenharmony_ci 178462306a36Sopenharmony_cistatic struct aead_alg aes_gcm_alg = { 178562306a36Sopenharmony_ci .setkey = atmel_aes_gcm_setkey, 178662306a36Sopenharmony_ci .setauthsize = atmel_aes_gcm_setauthsize, 178762306a36Sopenharmony_ci .encrypt = atmel_aes_gcm_encrypt, 178862306a36Sopenharmony_ci .decrypt = atmel_aes_gcm_decrypt, 178962306a36Sopenharmony_ci .init = atmel_aes_gcm_init, 179062306a36Sopenharmony_ci .ivsize = GCM_AES_IV_SIZE, 179162306a36Sopenharmony_ci .maxauthsize = AES_BLOCK_SIZE, 179262306a36Sopenharmony_ci 179362306a36Sopenharmony_ci .base = { 179462306a36Sopenharmony_ci .cra_name = "gcm(aes)", 179562306a36Sopenharmony_ci .cra_driver_name = "atmel-gcm-aes", 179662306a36Sopenharmony_ci .cra_blocksize = 1, 179762306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_gcm_ctx), 179862306a36Sopenharmony_ci }, 179962306a36Sopenharmony_ci}; 180062306a36Sopenharmony_ci 180162306a36Sopenharmony_ci 180262306a36Sopenharmony_ci/* xts functions */ 180362306a36Sopenharmony_ci 180462306a36Sopenharmony_cistatic inline struct atmel_aes_xts_ctx * 180562306a36Sopenharmony_ciatmel_aes_xts_ctx_cast(struct atmel_aes_base_ctx *ctx) 180662306a36Sopenharmony_ci{ 180762306a36Sopenharmony_ci return container_of(ctx, struct atmel_aes_xts_ctx, base); 180862306a36Sopenharmony_ci} 180962306a36Sopenharmony_ci 181062306a36Sopenharmony_cistatic int atmel_aes_xts_process_data(struct atmel_aes_dev *dd); 181162306a36Sopenharmony_ci 181262306a36Sopenharmony_cistatic int atmel_aes_xts_start(struct atmel_aes_dev *dd) 181362306a36Sopenharmony_ci{ 181462306a36Sopenharmony_ci struct atmel_aes_xts_ctx *ctx = atmel_aes_xts_ctx_cast(dd->ctx); 181562306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 181662306a36Sopenharmony_ci struct atmel_aes_reqctx *rctx = skcipher_request_ctx(req); 181762306a36Sopenharmony_ci unsigned long flags; 181862306a36Sopenharmony_ci int err; 181962306a36Sopenharmony_ci 182062306a36Sopenharmony_ci atmel_aes_set_mode(dd, rctx); 182162306a36Sopenharmony_ci 182262306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 182362306a36Sopenharmony_ci if (err) 182462306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 182562306a36Sopenharmony_ci 182662306a36Sopenharmony_ci /* Compute the tweak value from req->iv with ecb(aes). */ 182762306a36Sopenharmony_ci flags = dd->flags; 182862306a36Sopenharmony_ci dd->flags &= ~AES_FLAGS_MODE_MASK; 182962306a36Sopenharmony_ci dd->flags |= (AES_FLAGS_ECB | AES_FLAGS_ENCRYPT); 183062306a36Sopenharmony_ci atmel_aes_write_ctrl_key(dd, false, NULL, 183162306a36Sopenharmony_ci ctx->key2, ctx->base.keylen); 183262306a36Sopenharmony_ci dd->flags = flags; 183362306a36Sopenharmony_ci 183462306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_IDATAR(0), req->iv); 183562306a36Sopenharmony_ci return atmel_aes_wait_for_data_ready(dd, atmel_aes_xts_process_data); 183662306a36Sopenharmony_ci} 183762306a36Sopenharmony_ci 183862306a36Sopenharmony_cistatic int atmel_aes_xts_process_data(struct atmel_aes_dev *dd) 183962306a36Sopenharmony_ci{ 184062306a36Sopenharmony_ci struct skcipher_request *req = skcipher_request_cast(dd->areq); 184162306a36Sopenharmony_ci bool use_dma = (req->cryptlen >= ATMEL_AES_DMA_THRESHOLD); 184262306a36Sopenharmony_ci u32 tweak[AES_BLOCK_SIZE / sizeof(u32)]; 184362306a36Sopenharmony_ci static const __le32 one[AES_BLOCK_SIZE / sizeof(u32)] = {cpu_to_le32(1), }; 184462306a36Sopenharmony_ci u8 *tweak_bytes = (u8 *)tweak; 184562306a36Sopenharmony_ci int i; 184662306a36Sopenharmony_ci 184762306a36Sopenharmony_ci /* Read the computed ciphered tweak value. */ 184862306a36Sopenharmony_ci atmel_aes_read_block(dd, AES_ODATAR(0), tweak); 184962306a36Sopenharmony_ci /* 185062306a36Sopenharmony_ci * Hardware quirk: 185162306a36Sopenharmony_ci * the order of the ciphered tweak bytes need to be reversed before 185262306a36Sopenharmony_ci * writing them into the ODATARx registers. 185362306a36Sopenharmony_ci */ 185462306a36Sopenharmony_ci for (i = 0; i < AES_BLOCK_SIZE/2; ++i) 185562306a36Sopenharmony_ci swap(tweak_bytes[i], tweak_bytes[AES_BLOCK_SIZE - 1 - i]); 185662306a36Sopenharmony_ci 185762306a36Sopenharmony_ci /* Process the data. */ 185862306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, use_dma, NULL); 185962306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_TWR(0), tweak); 186062306a36Sopenharmony_ci atmel_aes_write_block(dd, AES_ALPHAR(0), one); 186162306a36Sopenharmony_ci if (use_dma) 186262306a36Sopenharmony_ci return atmel_aes_dma_start(dd, req->src, req->dst, 186362306a36Sopenharmony_ci req->cryptlen, 186462306a36Sopenharmony_ci atmel_aes_transfer_complete); 186562306a36Sopenharmony_ci 186662306a36Sopenharmony_ci return atmel_aes_cpu_start(dd, req->src, req->dst, req->cryptlen, 186762306a36Sopenharmony_ci atmel_aes_transfer_complete); 186862306a36Sopenharmony_ci} 186962306a36Sopenharmony_ci 187062306a36Sopenharmony_cistatic int atmel_aes_xts_setkey(struct crypto_skcipher *tfm, const u8 *key, 187162306a36Sopenharmony_ci unsigned int keylen) 187262306a36Sopenharmony_ci{ 187362306a36Sopenharmony_ci struct atmel_aes_xts_ctx *ctx = crypto_skcipher_ctx(tfm); 187462306a36Sopenharmony_ci int err; 187562306a36Sopenharmony_ci 187662306a36Sopenharmony_ci err = xts_verify_key(tfm, key, keylen); 187762306a36Sopenharmony_ci if (err) 187862306a36Sopenharmony_ci return err; 187962306a36Sopenharmony_ci 188062306a36Sopenharmony_ci crypto_skcipher_clear_flags(ctx->fallback_tfm, CRYPTO_TFM_REQ_MASK); 188162306a36Sopenharmony_ci crypto_skcipher_set_flags(ctx->fallback_tfm, tfm->base.crt_flags & 188262306a36Sopenharmony_ci CRYPTO_TFM_REQ_MASK); 188362306a36Sopenharmony_ci err = crypto_skcipher_setkey(ctx->fallback_tfm, key, keylen); 188462306a36Sopenharmony_ci if (err) 188562306a36Sopenharmony_ci return err; 188662306a36Sopenharmony_ci 188762306a36Sopenharmony_ci memcpy(ctx->base.key, key, keylen/2); 188862306a36Sopenharmony_ci memcpy(ctx->key2, key + keylen/2, keylen/2); 188962306a36Sopenharmony_ci ctx->base.keylen = keylen/2; 189062306a36Sopenharmony_ci 189162306a36Sopenharmony_ci return 0; 189262306a36Sopenharmony_ci} 189362306a36Sopenharmony_ci 189462306a36Sopenharmony_cistatic int atmel_aes_xts_encrypt(struct skcipher_request *req) 189562306a36Sopenharmony_ci{ 189662306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_XTS | AES_FLAGS_ENCRYPT); 189762306a36Sopenharmony_ci} 189862306a36Sopenharmony_ci 189962306a36Sopenharmony_cistatic int atmel_aes_xts_decrypt(struct skcipher_request *req) 190062306a36Sopenharmony_ci{ 190162306a36Sopenharmony_ci return atmel_aes_crypt(req, AES_FLAGS_XTS); 190262306a36Sopenharmony_ci} 190362306a36Sopenharmony_ci 190462306a36Sopenharmony_cistatic int atmel_aes_xts_init_tfm(struct crypto_skcipher *tfm) 190562306a36Sopenharmony_ci{ 190662306a36Sopenharmony_ci struct atmel_aes_xts_ctx *ctx = crypto_skcipher_ctx(tfm); 190762306a36Sopenharmony_ci struct atmel_aes_dev *dd; 190862306a36Sopenharmony_ci const char *tfm_name = crypto_tfm_alg_name(&tfm->base); 190962306a36Sopenharmony_ci 191062306a36Sopenharmony_ci dd = atmel_aes_dev_alloc(&ctx->base); 191162306a36Sopenharmony_ci if (!dd) 191262306a36Sopenharmony_ci return -ENODEV; 191362306a36Sopenharmony_ci 191462306a36Sopenharmony_ci ctx->fallback_tfm = crypto_alloc_skcipher(tfm_name, 0, 191562306a36Sopenharmony_ci CRYPTO_ALG_NEED_FALLBACK); 191662306a36Sopenharmony_ci if (IS_ERR(ctx->fallback_tfm)) 191762306a36Sopenharmony_ci return PTR_ERR(ctx->fallback_tfm); 191862306a36Sopenharmony_ci 191962306a36Sopenharmony_ci crypto_skcipher_set_reqsize(tfm, sizeof(struct atmel_aes_reqctx) + 192062306a36Sopenharmony_ci crypto_skcipher_reqsize(ctx->fallback_tfm)); 192162306a36Sopenharmony_ci ctx->base.dd = dd; 192262306a36Sopenharmony_ci ctx->base.start = atmel_aes_xts_start; 192362306a36Sopenharmony_ci 192462306a36Sopenharmony_ci return 0; 192562306a36Sopenharmony_ci} 192662306a36Sopenharmony_ci 192762306a36Sopenharmony_cistatic void atmel_aes_xts_exit_tfm(struct crypto_skcipher *tfm) 192862306a36Sopenharmony_ci{ 192962306a36Sopenharmony_ci struct atmel_aes_xts_ctx *ctx = crypto_skcipher_ctx(tfm); 193062306a36Sopenharmony_ci 193162306a36Sopenharmony_ci crypto_free_skcipher(ctx->fallback_tfm); 193262306a36Sopenharmony_ci} 193362306a36Sopenharmony_ci 193462306a36Sopenharmony_cistatic struct skcipher_alg aes_xts_alg = { 193562306a36Sopenharmony_ci .base.cra_name = "xts(aes)", 193662306a36Sopenharmony_ci .base.cra_driver_name = "atmel-xts-aes", 193762306a36Sopenharmony_ci .base.cra_blocksize = AES_BLOCK_SIZE, 193862306a36Sopenharmony_ci .base.cra_ctxsize = sizeof(struct atmel_aes_xts_ctx), 193962306a36Sopenharmony_ci .base.cra_flags = CRYPTO_ALG_NEED_FALLBACK, 194062306a36Sopenharmony_ci 194162306a36Sopenharmony_ci .min_keysize = 2 * AES_MIN_KEY_SIZE, 194262306a36Sopenharmony_ci .max_keysize = 2 * AES_MAX_KEY_SIZE, 194362306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 194462306a36Sopenharmony_ci .setkey = atmel_aes_xts_setkey, 194562306a36Sopenharmony_ci .encrypt = atmel_aes_xts_encrypt, 194662306a36Sopenharmony_ci .decrypt = atmel_aes_xts_decrypt, 194762306a36Sopenharmony_ci .init = atmel_aes_xts_init_tfm, 194862306a36Sopenharmony_ci .exit = atmel_aes_xts_exit_tfm, 194962306a36Sopenharmony_ci}; 195062306a36Sopenharmony_ci 195162306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 195262306a36Sopenharmony_ci/* authenc aead functions */ 195362306a36Sopenharmony_ci 195462306a36Sopenharmony_cistatic int atmel_aes_authenc_start(struct atmel_aes_dev *dd); 195562306a36Sopenharmony_cistatic int atmel_aes_authenc_init(struct atmel_aes_dev *dd, int err, 195662306a36Sopenharmony_ci bool is_async); 195762306a36Sopenharmony_cistatic int atmel_aes_authenc_transfer(struct atmel_aes_dev *dd, int err, 195862306a36Sopenharmony_ci bool is_async); 195962306a36Sopenharmony_cistatic int atmel_aes_authenc_digest(struct atmel_aes_dev *dd); 196062306a36Sopenharmony_cistatic int atmel_aes_authenc_final(struct atmel_aes_dev *dd, int err, 196162306a36Sopenharmony_ci bool is_async); 196262306a36Sopenharmony_ci 196362306a36Sopenharmony_cistatic void atmel_aes_authenc_complete(struct atmel_aes_dev *dd, int err) 196462306a36Sopenharmony_ci{ 196562306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 196662306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 196762306a36Sopenharmony_ci 196862306a36Sopenharmony_ci if (err && (dd->flags & AES_FLAGS_OWN_SHA)) 196962306a36Sopenharmony_ci atmel_sha_authenc_abort(&rctx->auth_req); 197062306a36Sopenharmony_ci dd->flags &= ~AES_FLAGS_OWN_SHA; 197162306a36Sopenharmony_ci} 197262306a36Sopenharmony_ci 197362306a36Sopenharmony_cistatic int atmel_aes_authenc_start(struct atmel_aes_dev *dd) 197462306a36Sopenharmony_ci{ 197562306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 197662306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 197762306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 197862306a36Sopenharmony_ci struct atmel_aes_authenc_ctx *ctx = crypto_aead_ctx(tfm); 197962306a36Sopenharmony_ci int err; 198062306a36Sopenharmony_ci 198162306a36Sopenharmony_ci atmel_aes_set_mode(dd, &rctx->base); 198262306a36Sopenharmony_ci 198362306a36Sopenharmony_ci err = atmel_aes_hw_init(dd); 198462306a36Sopenharmony_ci if (err) 198562306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 198662306a36Sopenharmony_ci 198762306a36Sopenharmony_ci return atmel_sha_authenc_schedule(&rctx->auth_req, ctx->auth, 198862306a36Sopenharmony_ci atmel_aes_authenc_init, dd); 198962306a36Sopenharmony_ci} 199062306a36Sopenharmony_ci 199162306a36Sopenharmony_cistatic int atmel_aes_authenc_init(struct atmel_aes_dev *dd, int err, 199262306a36Sopenharmony_ci bool is_async) 199362306a36Sopenharmony_ci{ 199462306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 199562306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 199662306a36Sopenharmony_ci 199762306a36Sopenharmony_ci if (is_async) 199862306a36Sopenharmony_ci dd->is_async = true; 199962306a36Sopenharmony_ci if (err) 200062306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 200162306a36Sopenharmony_ci 200262306a36Sopenharmony_ci /* If here, we've got the ownership of the SHA device. */ 200362306a36Sopenharmony_ci dd->flags |= AES_FLAGS_OWN_SHA; 200462306a36Sopenharmony_ci 200562306a36Sopenharmony_ci /* Configure the SHA device. */ 200662306a36Sopenharmony_ci return atmel_sha_authenc_init(&rctx->auth_req, 200762306a36Sopenharmony_ci req->src, req->assoclen, 200862306a36Sopenharmony_ci rctx->textlen, 200962306a36Sopenharmony_ci atmel_aes_authenc_transfer, dd); 201062306a36Sopenharmony_ci} 201162306a36Sopenharmony_ci 201262306a36Sopenharmony_cistatic int atmel_aes_authenc_transfer(struct atmel_aes_dev *dd, int err, 201362306a36Sopenharmony_ci bool is_async) 201462306a36Sopenharmony_ci{ 201562306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 201662306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 201762306a36Sopenharmony_ci bool enc = atmel_aes_is_encrypt(dd); 201862306a36Sopenharmony_ci struct scatterlist *src, *dst; 201962306a36Sopenharmony_ci __be32 iv[AES_BLOCK_SIZE / sizeof(u32)]; 202062306a36Sopenharmony_ci u32 emr; 202162306a36Sopenharmony_ci 202262306a36Sopenharmony_ci if (is_async) 202362306a36Sopenharmony_ci dd->is_async = true; 202462306a36Sopenharmony_ci if (err) 202562306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 202662306a36Sopenharmony_ci 202762306a36Sopenharmony_ci /* Prepare src and dst scatter-lists to transfer cipher/plain texts. */ 202862306a36Sopenharmony_ci src = scatterwalk_ffwd(rctx->src, req->src, req->assoclen); 202962306a36Sopenharmony_ci dst = src; 203062306a36Sopenharmony_ci 203162306a36Sopenharmony_ci if (req->src != req->dst) 203262306a36Sopenharmony_ci dst = scatterwalk_ffwd(rctx->dst, req->dst, req->assoclen); 203362306a36Sopenharmony_ci 203462306a36Sopenharmony_ci /* Configure the AES device. */ 203562306a36Sopenharmony_ci memcpy(iv, req->iv, sizeof(iv)); 203662306a36Sopenharmony_ci 203762306a36Sopenharmony_ci /* 203862306a36Sopenharmony_ci * Here we always set the 2nd parameter of atmel_aes_write_ctrl() to 203962306a36Sopenharmony_ci * 'true' even if the data transfer is actually performed by the CPU (so 204062306a36Sopenharmony_ci * not by the DMA) because we must force the AES_MR_SMOD bitfield to the 204162306a36Sopenharmony_ci * value AES_MR_SMOD_IDATAR0. Indeed, both AES_MR_SMOD and SHA_MR_SMOD 204262306a36Sopenharmony_ci * must be set to *_MR_SMOD_IDATAR0. 204362306a36Sopenharmony_ci */ 204462306a36Sopenharmony_ci atmel_aes_write_ctrl(dd, true, iv); 204562306a36Sopenharmony_ci emr = AES_EMR_PLIPEN; 204662306a36Sopenharmony_ci if (!enc) 204762306a36Sopenharmony_ci emr |= AES_EMR_PLIPD; 204862306a36Sopenharmony_ci atmel_aes_write(dd, AES_EMR, emr); 204962306a36Sopenharmony_ci 205062306a36Sopenharmony_ci /* Transfer data. */ 205162306a36Sopenharmony_ci return atmel_aes_dma_start(dd, src, dst, rctx->textlen, 205262306a36Sopenharmony_ci atmel_aes_authenc_digest); 205362306a36Sopenharmony_ci} 205462306a36Sopenharmony_ci 205562306a36Sopenharmony_cistatic int atmel_aes_authenc_digest(struct atmel_aes_dev *dd) 205662306a36Sopenharmony_ci{ 205762306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 205862306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 205962306a36Sopenharmony_ci 206062306a36Sopenharmony_ci /* atmel_sha_authenc_final() releases the SHA device. */ 206162306a36Sopenharmony_ci dd->flags &= ~AES_FLAGS_OWN_SHA; 206262306a36Sopenharmony_ci return atmel_sha_authenc_final(&rctx->auth_req, 206362306a36Sopenharmony_ci rctx->digest, sizeof(rctx->digest), 206462306a36Sopenharmony_ci atmel_aes_authenc_final, dd); 206562306a36Sopenharmony_ci} 206662306a36Sopenharmony_ci 206762306a36Sopenharmony_cistatic int atmel_aes_authenc_final(struct atmel_aes_dev *dd, int err, 206862306a36Sopenharmony_ci bool is_async) 206962306a36Sopenharmony_ci{ 207062306a36Sopenharmony_ci struct aead_request *req = aead_request_cast(dd->areq); 207162306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 207262306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 207362306a36Sopenharmony_ci bool enc = atmel_aes_is_encrypt(dd); 207462306a36Sopenharmony_ci u32 idigest[SHA512_DIGEST_SIZE / sizeof(u32)], *odigest = rctx->digest; 207562306a36Sopenharmony_ci u32 offs, authsize; 207662306a36Sopenharmony_ci 207762306a36Sopenharmony_ci if (is_async) 207862306a36Sopenharmony_ci dd->is_async = true; 207962306a36Sopenharmony_ci if (err) 208062306a36Sopenharmony_ci goto complete; 208162306a36Sopenharmony_ci 208262306a36Sopenharmony_ci offs = req->assoclen + rctx->textlen; 208362306a36Sopenharmony_ci authsize = crypto_aead_authsize(tfm); 208462306a36Sopenharmony_ci if (enc) { 208562306a36Sopenharmony_ci scatterwalk_map_and_copy(odigest, req->dst, offs, authsize, 1); 208662306a36Sopenharmony_ci } else { 208762306a36Sopenharmony_ci scatterwalk_map_and_copy(idigest, req->src, offs, authsize, 0); 208862306a36Sopenharmony_ci if (crypto_memneq(idigest, odigest, authsize)) 208962306a36Sopenharmony_ci err = -EBADMSG; 209062306a36Sopenharmony_ci } 209162306a36Sopenharmony_ci 209262306a36Sopenharmony_cicomplete: 209362306a36Sopenharmony_ci return atmel_aes_complete(dd, err); 209462306a36Sopenharmony_ci} 209562306a36Sopenharmony_ci 209662306a36Sopenharmony_cistatic int atmel_aes_authenc_setkey(struct crypto_aead *tfm, const u8 *key, 209762306a36Sopenharmony_ci unsigned int keylen) 209862306a36Sopenharmony_ci{ 209962306a36Sopenharmony_ci struct atmel_aes_authenc_ctx *ctx = crypto_aead_ctx(tfm); 210062306a36Sopenharmony_ci struct crypto_authenc_keys keys; 210162306a36Sopenharmony_ci int err; 210262306a36Sopenharmony_ci 210362306a36Sopenharmony_ci if (crypto_authenc_extractkeys(&keys, key, keylen) != 0) 210462306a36Sopenharmony_ci goto badkey; 210562306a36Sopenharmony_ci 210662306a36Sopenharmony_ci if (keys.enckeylen > sizeof(ctx->base.key)) 210762306a36Sopenharmony_ci goto badkey; 210862306a36Sopenharmony_ci 210962306a36Sopenharmony_ci /* Save auth key. */ 211062306a36Sopenharmony_ci err = atmel_sha_authenc_setkey(ctx->auth, 211162306a36Sopenharmony_ci keys.authkey, keys.authkeylen, 211262306a36Sopenharmony_ci crypto_aead_get_flags(tfm)); 211362306a36Sopenharmony_ci if (err) { 211462306a36Sopenharmony_ci memzero_explicit(&keys, sizeof(keys)); 211562306a36Sopenharmony_ci return err; 211662306a36Sopenharmony_ci } 211762306a36Sopenharmony_ci 211862306a36Sopenharmony_ci /* Save enc key. */ 211962306a36Sopenharmony_ci ctx->base.keylen = keys.enckeylen; 212062306a36Sopenharmony_ci memcpy(ctx->base.key, keys.enckey, keys.enckeylen); 212162306a36Sopenharmony_ci 212262306a36Sopenharmony_ci memzero_explicit(&keys, sizeof(keys)); 212362306a36Sopenharmony_ci return 0; 212462306a36Sopenharmony_ci 212562306a36Sopenharmony_cibadkey: 212662306a36Sopenharmony_ci memzero_explicit(&keys, sizeof(keys)); 212762306a36Sopenharmony_ci return -EINVAL; 212862306a36Sopenharmony_ci} 212962306a36Sopenharmony_ci 213062306a36Sopenharmony_cistatic int atmel_aes_authenc_init_tfm(struct crypto_aead *tfm, 213162306a36Sopenharmony_ci unsigned long auth_mode) 213262306a36Sopenharmony_ci{ 213362306a36Sopenharmony_ci struct atmel_aes_authenc_ctx *ctx = crypto_aead_ctx(tfm); 213462306a36Sopenharmony_ci unsigned int auth_reqsize = atmel_sha_authenc_get_reqsize(); 213562306a36Sopenharmony_ci struct atmel_aes_dev *dd; 213662306a36Sopenharmony_ci 213762306a36Sopenharmony_ci dd = atmel_aes_dev_alloc(&ctx->base); 213862306a36Sopenharmony_ci if (!dd) 213962306a36Sopenharmony_ci return -ENODEV; 214062306a36Sopenharmony_ci 214162306a36Sopenharmony_ci ctx->auth = atmel_sha_authenc_spawn(auth_mode); 214262306a36Sopenharmony_ci if (IS_ERR(ctx->auth)) 214362306a36Sopenharmony_ci return PTR_ERR(ctx->auth); 214462306a36Sopenharmony_ci 214562306a36Sopenharmony_ci crypto_aead_set_reqsize(tfm, (sizeof(struct atmel_aes_authenc_reqctx) + 214662306a36Sopenharmony_ci auth_reqsize)); 214762306a36Sopenharmony_ci ctx->base.dd = dd; 214862306a36Sopenharmony_ci ctx->base.start = atmel_aes_authenc_start; 214962306a36Sopenharmony_ci 215062306a36Sopenharmony_ci return 0; 215162306a36Sopenharmony_ci} 215262306a36Sopenharmony_ci 215362306a36Sopenharmony_cistatic int atmel_aes_authenc_hmac_sha1_init_tfm(struct crypto_aead *tfm) 215462306a36Sopenharmony_ci{ 215562306a36Sopenharmony_ci return atmel_aes_authenc_init_tfm(tfm, SHA_FLAGS_HMAC_SHA1); 215662306a36Sopenharmony_ci} 215762306a36Sopenharmony_ci 215862306a36Sopenharmony_cistatic int atmel_aes_authenc_hmac_sha224_init_tfm(struct crypto_aead *tfm) 215962306a36Sopenharmony_ci{ 216062306a36Sopenharmony_ci return atmel_aes_authenc_init_tfm(tfm, SHA_FLAGS_HMAC_SHA224); 216162306a36Sopenharmony_ci} 216262306a36Sopenharmony_ci 216362306a36Sopenharmony_cistatic int atmel_aes_authenc_hmac_sha256_init_tfm(struct crypto_aead *tfm) 216462306a36Sopenharmony_ci{ 216562306a36Sopenharmony_ci return atmel_aes_authenc_init_tfm(tfm, SHA_FLAGS_HMAC_SHA256); 216662306a36Sopenharmony_ci} 216762306a36Sopenharmony_ci 216862306a36Sopenharmony_cistatic int atmel_aes_authenc_hmac_sha384_init_tfm(struct crypto_aead *tfm) 216962306a36Sopenharmony_ci{ 217062306a36Sopenharmony_ci return atmel_aes_authenc_init_tfm(tfm, SHA_FLAGS_HMAC_SHA384); 217162306a36Sopenharmony_ci} 217262306a36Sopenharmony_ci 217362306a36Sopenharmony_cistatic int atmel_aes_authenc_hmac_sha512_init_tfm(struct crypto_aead *tfm) 217462306a36Sopenharmony_ci{ 217562306a36Sopenharmony_ci return atmel_aes_authenc_init_tfm(tfm, SHA_FLAGS_HMAC_SHA512); 217662306a36Sopenharmony_ci} 217762306a36Sopenharmony_ci 217862306a36Sopenharmony_cistatic void atmel_aes_authenc_exit_tfm(struct crypto_aead *tfm) 217962306a36Sopenharmony_ci{ 218062306a36Sopenharmony_ci struct atmel_aes_authenc_ctx *ctx = crypto_aead_ctx(tfm); 218162306a36Sopenharmony_ci 218262306a36Sopenharmony_ci atmel_sha_authenc_free(ctx->auth); 218362306a36Sopenharmony_ci} 218462306a36Sopenharmony_ci 218562306a36Sopenharmony_cistatic int atmel_aes_authenc_crypt(struct aead_request *req, 218662306a36Sopenharmony_ci unsigned long mode) 218762306a36Sopenharmony_ci{ 218862306a36Sopenharmony_ci struct atmel_aes_authenc_reqctx *rctx = aead_request_ctx(req); 218962306a36Sopenharmony_ci struct crypto_aead *tfm = crypto_aead_reqtfm(req); 219062306a36Sopenharmony_ci struct atmel_aes_base_ctx *ctx = crypto_aead_ctx(tfm); 219162306a36Sopenharmony_ci u32 authsize = crypto_aead_authsize(tfm); 219262306a36Sopenharmony_ci bool enc = (mode & AES_FLAGS_ENCRYPT); 219362306a36Sopenharmony_ci 219462306a36Sopenharmony_ci /* Compute text length. */ 219562306a36Sopenharmony_ci if (!enc && req->cryptlen < authsize) 219662306a36Sopenharmony_ci return -EINVAL; 219762306a36Sopenharmony_ci rctx->textlen = req->cryptlen - (enc ? 0 : authsize); 219862306a36Sopenharmony_ci 219962306a36Sopenharmony_ci /* 220062306a36Sopenharmony_ci * Currently, empty messages are not supported yet: 220162306a36Sopenharmony_ci * the SHA auto-padding can be used only on non-empty messages. 220262306a36Sopenharmony_ci * Hence a special case needs to be implemented for empty message. 220362306a36Sopenharmony_ci */ 220462306a36Sopenharmony_ci if (!rctx->textlen && !req->assoclen) 220562306a36Sopenharmony_ci return -EINVAL; 220662306a36Sopenharmony_ci 220762306a36Sopenharmony_ci rctx->base.mode = mode; 220862306a36Sopenharmony_ci ctx->block_size = AES_BLOCK_SIZE; 220962306a36Sopenharmony_ci ctx->is_aead = true; 221062306a36Sopenharmony_ci 221162306a36Sopenharmony_ci return atmel_aes_handle_queue(ctx->dd, &req->base); 221262306a36Sopenharmony_ci} 221362306a36Sopenharmony_ci 221462306a36Sopenharmony_cistatic int atmel_aes_authenc_cbc_aes_encrypt(struct aead_request *req) 221562306a36Sopenharmony_ci{ 221662306a36Sopenharmony_ci return atmel_aes_authenc_crypt(req, AES_FLAGS_CBC | AES_FLAGS_ENCRYPT); 221762306a36Sopenharmony_ci} 221862306a36Sopenharmony_ci 221962306a36Sopenharmony_cistatic int atmel_aes_authenc_cbc_aes_decrypt(struct aead_request *req) 222062306a36Sopenharmony_ci{ 222162306a36Sopenharmony_ci return atmel_aes_authenc_crypt(req, AES_FLAGS_CBC); 222262306a36Sopenharmony_ci} 222362306a36Sopenharmony_ci 222462306a36Sopenharmony_cistatic struct aead_alg aes_authenc_algs[] = { 222562306a36Sopenharmony_ci{ 222662306a36Sopenharmony_ci .setkey = atmel_aes_authenc_setkey, 222762306a36Sopenharmony_ci .encrypt = atmel_aes_authenc_cbc_aes_encrypt, 222862306a36Sopenharmony_ci .decrypt = atmel_aes_authenc_cbc_aes_decrypt, 222962306a36Sopenharmony_ci .init = atmel_aes_authenc_hmac_sha1_init_tfm, 223062306a36Sopenharmony_ci .exit = atmel_aes_authenc_exit_tfm, 223162306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 223262306a36Sopenharmony_ci .maxauthsize = SHA1_DIGEST_SIZE, 223362306a36Sopenharmony_ci 223462306a36Sopenharmony_ci .base = { 223562306a36Sopenharmony_ci .cra_name = "authenc(hmac(sha1),cbc(aes))", 223662306a36Sopenharmony_ci .cra_driver_name = "atmel-authenc-hmac-sha1-cbc-aes", 223762306a36Sopenharmony_ci .cra_blocksize = AES_BLOCK_SIZE, 223862306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_authenc_ctx), 223962306a36Sopenharmony_ci }, 224062306a36Sopenharmony_ci}, 224162306a36Sopenharmony_ci{ 224262306a36Sopenharmony_ci .setkey = atmel_aes_authenc_setkey, 224362306a36Sopenharmony_ci .encrypt = atmel_aes_authenc_cbc_aes_encrypt, 224462306a36Sopenharmony_ci .decrypt = atmel_aes_authenc_cbc_aes_decrypt, 224562306a36Sopenharmony_ci .init = atmel_aes_authenc_hmac_sha224_init_tfm, 224662306a36Sopenharmony_ci .exit = atmel_aes_authenc_exit_tfm, 224762306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 224862306a36Sopenharmony_ci .maxauthsize = SHA224_DIGEST_SIZE, 224962306a36Sopenharmony_ci 225062306a36Sopenharmony_ci .base = { 225162306a36Sopenharmony_ci .cra_name = "authenc(hmac(sha224),cbc(aes))", 225262306a36Sopenharmony_ci .cra_driver_name = "atmel-authenc-hmac-sha224-cbc-aes", 225362306a36Sopenharmony_ci .cra_blocksize = AES_BLOCK_SIZE, 225462306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_authenc_ctx), 225562306a36Sopenharmony_ci }, 225662306a36Sopenharmony_ci}, 225762306a36Sopenharmony_ci{ 225862306a36Sopenharmony_ci .setkey = atmel_aes_authenc_setkey, 225962306a36Sopenharmony_ci .encrypt = atmel_aes_authenc_cbc_aes_encrypt, 226062306a36Sopenharmony_ci .decrypt = atmel_aes_authenc_cbc_aes_decrypt, 226162306a36Sopenharmony_ci .init = atmel_aes_authenc_hmac_sha256_init_tfm, 226262306a36Sopenharmony_ci .exit = atmel_aes_authenc_exit_tfm, 226362306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 226462306a36Sopenharmony_ci .maxauthsize = SHA256_DIGEST_SIZE, 226562306a36Sopenharmony_ci 226662306a36Sopenharmony_ci .base = { 226762306a36Sopenharmony_ci .cra_name = "authenc(hmac(sha256),cbc(aes))", 226862306a36Sopenharmony_ci .cra_driver_name = "atmel-authenc-hmac-sha256-cbc-aes", 226962306a36Sopenharmony_ci .cra_blocksize = AES_BLOCK_SIZE, 227062306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_authenc_ctx), 227162306a36Sopenharmony_ci }, 227262306a36Sopenharmony_ci}, 227362306a36Sopenharmony_ci{ 227462306a36Sopenharmony_ci .setkey = atmel_aes_authenc_setkey, 227562306a36Sopenharmony_ci .encrypt = atmel_aes_authenc_cbc_aes_encrypt, 227662306a36Sopenharmony_ci .decrypt = atmel_aes_authenc_cbc_aes_decrypt, 227762306a36Sopenharmony_ci .init = atmel_aes_authenc_hmac_sha384_init_tfm, 227862306a36Sopenharmony_ci .exit = atmel_aes_authenc_exit_tfm, 227962306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 228062306a36Sopenharmony_ci .maxauthsize = SHA384_DIGEST_SIZE, 228162306a36Sopenharmony_ci 228262306a36Sopenharmony_ci .base = { 228362306a36Sopenharmony_ci .cra_name = "authenc(hmac(sha384),cbc(aes))", 228462306a36Sopenharmony_ci .cra_driver_name = "atmel-authenc-hmac-sha384-cbc-aes", 228562306a36Sopenharmony_ci .cra_blocksize = AES_BLOCK_SIZE, 228662306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_authenc_ctx), 228762306a36Sopenharmony_ci }, 228862306a36Sopenharmony_ci}, 228962306a36Sopenharmony_ci{ 229062306a36Sopenharmony_ci .setkey = atmel_aes_authenc_setkey, 229162306a36Sopenharmony_ci .encrypt = atmel_aes_authenc_cbc_aes_encrypt, 229262306a36Sopenharmony_ci .decrypt = atmel_aes_authenc_cbc_aes_decrypt, 229362306a36Sopenharmony_ci .init = atmel_aes_authenc_hmac_sha512_init_tfm, 229462306a36Sopenharmony_ci .exit = atmel_aes_authenc_exit_tfm, 229562306a36Sopenharmony_ci .ivsize = AES_BLOCK_SIZE, 229662306a36Sopenharmony_ci .maxauthsize = SHA512_DIGEST_SIZE, 229762306a36Sopenharmony_ci 229862306a36Sopenharmony_ci .base = { 229962306a36Sopenharmony_ci .cra_name = "authenc(hmac(sha512),cbc(aes))", 230062306a36Sopenharmony_ci .cra_driver_name = "atmel-authenc-hmac-sha512-cbc-aes", 230162306a36Sopenharmony_ci .cra_blocksize = AES_BLOCK_SIZE, 230262306a36Sopenharmony_ci .cra_ctxsize = sizeof(struct atmel_aes_authenc_ctx), 230362306a36Sopenharmony_ci }, 230462306a36Sopenharmony_ci}, 230562306a36Sopenharmony_ci}; 230662306a36Sopenharmony_ci#endif /* CONFIG_CRYPTO_DEV_ATMEL_AUTHENC */ 230762306a36Sopenharmony_ci 230862306a36Sopenharmony_ci/* Probe functions */ 230962306a36Sopenharmony_ci 231062306a36Sopenharmony_cistatic int atmel_aes_buff_init(struct atmel_aes_dev *dd) 231162306a36Sopenharmony_ci{ 231262306a36Sopenharmony_ci dd->buf = (void *)__get_free_pages(GFP_KERNEL, ATMEL_AES_BUFFER_ORDER); 231362306a36Sopenharmony_ci dd->buflen = ATMEL_AES_BUFFER_SIZE; 231462306a36Sopenharmony_ci dd->buflen &= ~(AES_BLOCK_SIZE - 1); 231562306a36Sopenharmony_ci 231662306a36Sopenharmony_ci if (!dd->buf) { 231762306a36Sopenharmony_ci dev_err(dd->dev, "unable to alloc pages.\n"); 231862306a36Sopenharmony_ci return -ENOMEM; 231962306a36Sopenharmony_ci } 232062306a36Sopenharmony_ci 232162306a36Sopenharmony_ci return 0; 232262306a36Sopenharmony_ci} 232362306a36Sopenharmony_ci 232462306a36Sopenharmony_cistatic void atmel_aes_buff_cleanup(struct atmel_aes_dev *dd) 232562306a36Sopenharmony_ci{ 232662306a36Sopenharmony_ci free_page((unsigned long)dd->buf); 232762306a36Sopenharmony_ci} 232862306a36Sopenharmony_ci 232962306a36Sopenharmony_cistatic int atmel_aes_dma_init(struct atmel_aes_dev *dd) 233062306a36Sopenharmony_ci{ 233162306a36Sopenharmony_ci int ret; 233262306a36Sopenharmony_ci 233362306a36Sopenharmony_ci /* Try to grab 2 DMA channels */ 233462306a36Sopenharmony_ci dd->src.chan = dma_request_chan(dd->dev, "tx"); 233562306a36Sopenharmony_ci if (IS_ERR(dd->src.chan)) { 233662306a36Sopenharmony_ci ret = PTR_ERR(dd->src.chan); 233762306a36Sopenharmony_ci goto err_dma_in; 233862306a36Sopenharmony_ci } 233962306a36Sopenharmony_ci 234062306a36Sopenharmony_ci dd->dst.chan = dma_request_chan(dd->dev, "rx"); 234162306a36Sopenharmony_ci if (IS_ERR(dd->dst.chan)) { 234262306a36Sopenharmony_ci ret = PTR_ERR(dd->dst.chan); 234362306a36Sopenharmony_ci goto err_dma_out; 234462306a36Sopenharmony_ci } 234562306a36Sopenharmony_ci 234662306a36Sopenharmony_ci return 0; 234762306a36Sopenharmony_ci 234862306a36Sopenharmony_cierr_dma_out: 234962306a36Sopenharmony_ci dma_release_channel(dd->src.chan); 235062306a36Sopenharmony_cierr_dma_in: 235162306a36Sopenharmony_ci dev_err(dd->dev, "no DMA channel available\n"); 235262306a36Sopenharmony_ci return ret; 235362306a36Sopenharmony_ci} 235462306a36Sopenharmony_ci 235562306a36Sopenharmony_cistatic void atmel_aes_dma_cleanup(struct atmel_aes_dev *dd) 235662306a36Sopenharmony_ci{ 235762306a36Sopenharmony_ci dma_release_channel(dd->dst.chan); 235862306a36Sopenharmony_ci dma_release_channel(dd->src.chan); 235962306a36Sopenharmony_ci} 236062306a36Sopenharmony_ci 236162306a36Sopenharmony_cistatic void atmel_aes_queue_task(unsigned long data) 236262306a36Sopenharmony_ci{ 236362306a36Sopenharmony_ci struct atmel_aes_dev *dd = (struct atmel_aes_dev *)data; 236462306a36Sopenharmony_ci 236562306a36Sopenharmony_ci atmel_aes_handle_queue(dd, NULL); 236662306a36Sopenharmony_ci} 236762306a36Sopenharmony_ci 236862306a36Sopenharmony_cistatic void atmel_aes_done_task(unsigned long data) 236962306a36Sopenharmony_ci{ 237062306a36Sopenharmony_ci struct atmel_aes_dev *dd = (struct atmel_aes_dev *)data; 237162306a36Sopenharmony_ci 237262306a36Sopenharmony_ci dd->is_async = true; 237362306a36Sopenharmony_ci (void)dd->resume(dd); 237462306a36Sopenharmony_ci} 237562306a36Sopenharmony_ci 237662306a36Sopenharmony_cistatic irqreturn_t atmel_aes_irq(int irq, void *dev_id) 237762306a36Sopenharmony_ci{ 237862306a36Sopenharmony_ci struct atmel_aes_dev *aes_dd = dev_id; 237962306a36Sopenharmony_ci u32 reg; 238062306a36Sopenharmony_ci 238162306a36Sopenharmony_ci reg = atmel_aes_read(aes_dd, AES_ISR); 238262306a36Sopenharmony_ci if (reg & atmel_aes_read(aes_dd, AES_IMR)) { 238362306a36Sopenharmony_ci atmel_aes_write(aes_dd, AES_IDR, reg); 238462306a36Sopenharmony_ci if (AES_FLAGS_BUSY & aes_dd->flags) 238562306a36Sopenharmony_ci tasklet_schedule(&aes_dd->done_task); 238662306a36Sopenharmony_ci else 238762306a36Sopenharmony_ci dev_warn(aes_dd->dev, "AES interrupt when no active requests.\n"); 238862306a36Sopenharmony_ci return IRQ_HANDLED; 238962306a36Sopenharmony_ci } 239062306a36Sopenharmony_ci 239162306a36Sopenharmony_ci return IRQ_NONE; 239262306a36Sopenharmony_ci} 239362306a36Sopenharmony_ci 239462306a36Sopenharmony_cistatic void atmel_aes_unregister_algs(struct atmel_aes_dev *dd) 239562306a36Sopenharmony_ci{ 239662306a36Sopenharmony_ci int i; 239762306a36Sopenharmony_ci 239862306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 239962306a36Sopenharmony_ci if (dd->caps.has_authenc) 240062306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(aes_authenc_algs); i++) 240162306a36Sopenharmony_ci crypto_unregister_aead(&aes_authenc_algs[i]); 240262306a36Sopenharmony_ci#endif 240362306a36Sopenharmony_ci 240462306a36Sopenharmony_ci if (dd->caps.has_xts) 240562306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_xts_alg); 240662306a36Sopenharmony_ci 240762306a36Sopenharmony_ci if (dd->caps.has_gcm) 240862306a36Sopenharmony_ci crypto_unregister_aead(&aes_gcm_alg); 240962306a36Sopenharmony_ci 241062306a36Sopenharmony_ci if (dd->caps.has_cfb64) 241162306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_cfb64_alg); 241262306a36Sopenharmony_ci 241362306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(aes_algs); i++) 241462306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_algs[i]); 241562306a36Sopenharmony_ci} 241662306a36Sopenharmony_ci 241762306a36Sopenharmony_cistatic void atmel_aes_crypto_alg_init(struct crypto_alg *alg) 241862306a36Sopenharmony_ci{ 241962306a36Sopenharmony_ci alg->cra_flags |= CRYPTO_ALG_ASYNC; 242062306a36Sopenharmony_ci alg->cra_alignmask = 0xf; 242162306a36Sopenharmony_ci alg->cra_priority = ATMEL_AES_PRIORITY; 242262306a36Sopenharmony_ci alg->cra_module = THIS_MODULE; 242362306a36Sopenharmony_ci} 242462306a36Sopenharmony_ci 242562306a36Sopenharmony_cistatic int atmel_aes_register_algs(struct atmel_aes_dev *dd) 242662306a36Sopenharmony_ci{ 242762306a36Sopenharmony_ci int err, i, j; 242862306a36Sopenharmony_ci 242962306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(aes_algs); i++) { 243062306a36Sopenharmony_ci atmel_aes_crypto_alg_init(&aes_algs[i].base); 243162306a36Sopenharmony_ci 243262306a36Sopenharmony_ci err = crypto_register_skcipher(&aes_algs[i]); 243362306a36Sopenharmony_ci if (err) 243462306a36Sopenharmony_ci goto err_aes_algs; 243562306a36Sopenharmony_ci } 243662306a36Sopenharmony_ci 243762306a36Sopenharmony_ci if (dd->caps.has_cfb64) { 243862306a36Sopenharmony_ci atmel_aes_crypto_alg_init(&aes_cfb64_alg.base); 243962306a36Sopenharmony_ci 244062306a36Sopenharmony_ci err = crypto_register_skcipher(&aes_cfb64_alg); 244162306a36Sopenharmony_ci if (err) 244262306a36Sopenharmony_ci goto err_aes_cfb64_alg; 244362306a36Sopenharmony_ci } 244462306a36Sopenharmony_ci 244562306a36Sopenharmony_ci if (dd->caps.has_gcm) { 244662306a36Sopenharmony_ci atmel_aes_crypto_alg_init(&aes_gcm_alg.base); 244762306a36Sopenharmony_ci 244862306a36Sopenharmony_ci err = crypto_register_aead(&aes_gcm_alg); 244962306a36Sopenharmony_ci if (err) 245062306a36Sopenharmony_ci goto err_aes_gcm_alg; 245162306a36Sopenharmony_ci } 245262306a36Sopenharmony_ci 245362306a36Sopenharmony_ci if (dd->caps.has_xts) { 245462306a36Sopenharmony_ci atmel_aes_crypto_alg_init(&aes_xts_alg.base); 245562306a36Sopenharmony_ci 245662306a36Sopenharmony_ci err = crypto_register_skcipher(&aes_xts_alg); 245762306a36Sopenharmony_ci if (err) 245862306a36Sopenharmony_ci goto err_aes_xts_alg; 245962306a36Sopenharmony_ci } 246062306a36Sopenharmony_ci 246162306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 246262306a36Sopenharmony_ci if (dd->caps.has_authenc) { 246362306a36Sopenharmony_ci for (i = 0; i < ARRAY_SIZE(aes_authenc_algs); i++) { 246462306a36Sopenharmony_ci atmel_aes_crypto_alg_init(&aes_authenc_algs[i].base); 246562306a36Sopenharmony_ci 246662306a36Sopenharmony_ci err = crypto_register_aead(&aes_authenc_algs[i]); 246762306a36Sopenharmony_ci if (err) 246862306a36Sopenharmony_ci goto err_aes_authenc_alg; 246962306a36Sopenharmony_ci } 247062306a36Sopenharmony_ci } 247162306a36Sopenharmony_ci#endif 247262306a36Sopenharmony_ci 247362306a36Sopenharmony_ci return 0; 247462306a36Sopenharmony_ci 247562306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 247662306a36Sopenharmony_ci /* i = ARRAY_SIZE(aes_authenc_algs); */ 247762306a36Sopenharmony_cierr_aes_authenc_alg: 247862306a36Sopenharmony_ci for (j = 0; j < i; j++) 247962306a36Sopenharmony_ci crypto_unregister_aead(&aes_authenc_algs[j]); 248062306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_xts_alg); 248162306a36Sopenharmony_ci#endif 248262306a36Sopenharmony_cierr_aes_xts_alg: 248362306a36Sopenharmony_ci crypto_unregister_aead(&aes_gcm_alg); 248462306a36Sopenharmony_cierr_aes_gcm_alg: 248562306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_cfb64_alg); 248662306a36Sopenharmony_cierr_aes_cfb64_alg: 248762306a36Sopenharmony_ci i = ARRAY_SIZE(aes_algs); 248862306a36Sopenharmony_cierr_aes_algs: 248962306a36Sopenharmony_ci for (j = 0; j < i; j++) 249062306a36Sopenharmony_ci crypto_unregister_skcipher(&aes_algs[j]); 249162306a36Sopenharmony_ci 249262306a36Sopenharmony_ci return err; 249362306a36Sopenharmony_ci} 249462306a36Sopenharmony_ci 249562306a36Sopenharmony_cistatic void atmel_aes_get_cap(struct atmel_aes_dev *dd) 249662306a36Sopenharmony_ci{ 249762306a36Sopenharmony_ci dd->caps.has_dualbuff = 0; 249862306a36Sopenharmony_ci dd->caps.has_cfb64 = 0; 249962306a36Sopenharmony_ci dd->caps.has_gcm = 0; 250062306a36Sopenharmony_ci dd->caps.has_xts = 0; 250162306a36Sopenharmony_ci dd->caps.has_authenc = 0; 250262306a36Sopenharmony_ci dd->caps.max_burst_size = 1; 250362306a36Sopenharmony_ci 250462306a36Sopenharmony_ci /* keep only major version number */ 250562306a36Sopenharmony_ci switch (dd->hw_version & 0xff0) { 250662306a36Sopenharmony_ci case 0x700: 250762306a36Sopenharmony_ci case 0x600: 250862306a36Sopenharmony_ci case 0x500: 250962306a36Sopenharmony_ci dd->caps.has_dualbuff = 1; 251062306a36Sopenharmony_ci dd->caps.has_cfb64 = 1; 251162306a36Sopenharmony_ci dd->caps.has_gcm = 1; 251262306a36Sopenharmony_ci dd->caps.has_xts = 1; 251362306a36Sopenharmony_ci dd->caps.has_authenc = 1; 251462306a36Sopenharmony_ci dd->caps.max_burst_size = 4; 251562306a36Sopenharmony_ci break; 251662306a36Sopenharmony_ci case 0x200: 251762306a36Sopenharmony_ci dd->caps.has_dualbuff = 1; 251862306a36Sopenharmony_ci dd->caps.has_cfb64 = 1; 251962306a36Sopenharmony_ci dd->caps.has_gcm = 1; 252062306a36Sopenharmony_ci dd->caps.max_burst_size = 4; 252162306a36Sopenharmony_ci break; 252262306a36Sopenharmony_ci case 0x130: 252362306a36Sopenharmony_ci dd->caps.has_dualbuff = 1; 252462306a36Sopenharmony_ci dd->caps.has_cfb64 = 1; 252562306a36Sopenharmony_ci dd->caps.max_burst_size = 4; 252662306a36Sopenharmony_ci break; 252762306a36Sopenharmony_ci case 0x120: 252862306a36Sopenharmony_ci break; 252962306a36Sopenharmony_ci default: 253062306a36Sopenharmony_ci dev_warn(dd->dev, 253162306a36Sopenharmony_ci "Unmanaged aes version, set minimum capabilities\n"); 253262306a36Sopenharmony_ci break; 253362306a36Sopenharmony_ci } 253462306a36Sopenharmony_ci} 253562306a36Sopenharmony_ci 253662306a36Sopenharmony_cistatic const struct of_device_id atmel_aes_dt_ids[] = { 253762306a36Sopenharmony_ci { .compatible = "atmel,at91sam9g46-aes" }, 253862306a36Sopenharmony_ci { /* sentinel */ } 253962306a36Sopenharmony_ci}; 254062306a36Sopenharmony_ciMODULE_DEVICE_TABLE(of, atmel_aes_dt_ids); 254162306a36Sopenharmony_ci 254262306a36Sopenharmony_cistatic int atmel_aes_probe(struct platform_device *pdev) 254362306a36Sopenharmony_ci{ 254462306a36Sopenharmony_ci struct atmel_aes_dev *aes_dd; 254562306a36Sopenharmony_ci struct device *dev = &pdev->dev; 254662306a36Sopenharmony_ci struct resource *aes_res; 254762306a36Sopenharmony_ci int err; 254862306a36Sopenharmony_ci 254962306a36Sopenharmony_ci aes_dd = devm_kzalloc(&pdev->dev, sizeof(*aes_dd), GFP_KERNEL); 255062306a36Sopenharmony_ci if (!aes_dd) 255162306a36Sopenharmony_ci return -ENOMEM; 255262306a36Sopenharmony_ci 255362306a36Sopenharmony_ci aes_dd->dev = dev; 255462306a36Sopenharmony_ci 255562306a36Sopenharmony_ci platform_set_drvdata(pdev, aes_dd); 255662306a36Sopenharmony_ci 255762306a36Sopenharmony_ci INIT_LIST_HEAD(&aes_dd->list); 255862306a36Sopenharmony_ci spin_lock_init(&aes_dd->lock); 255962306a36Sopenharmony_ci 256062306a36Sopenharmony_ci tasklet_init(&aes_dd->done_task, atmel_aes_done_task, 256162306a36Sopenharmony_ci (unsigned long)aes_dd); 256262306a36Sopenharmony_ci tasklet_init(&aes_dd->queue_task, atmel_aes_queue_task, 256362306a36Sopenharmony_ci (unsigned long)aes_dd); 256462306a36Sopenharmony_ci 256562306a36Sopenharmony_ci crypto_init_queue(&aes_dd->queue, ATMEL_AES_QUEUE_LENGTH); 256662306a36Sopenharmony_ci 256762306a36Sopenharmony_ci aes_dd->io_base = devm_platform_get_and_ioremap_resource(pdev, 0, &aes_res); 256862306a36Sopenharmony_ci if (IS_ERR(aes_dd->io_base)) { 256962306a36Sopenharmony_ci err = PTR_ERR(aes_dd->io_base); 257062306a36Sopenharmony_ci goto err_tasklet_kill; 257162306a36Sopenharmony_ci } 257262306a36Sopenharmony_ci aes_dd->phys_base = aes_res->start; 257362306a36Sopenharmony_ci 257462306a36Sopenharmony_ci /* Get the IRQ */ 257562306a36Sopenharmony_ci aes_dd->irq = platform_get_irq(pdev, 0); 257662306a36Sopenharmony_ci if (aes_dd->irq < 0) { 257762306a36Sopenharmony_ci err = aes_dd->irq; 257862306a36Sopenharmony_ci goto err_tasklet_kill; 257962306a36Sopenharmony_ci } 258062306a36Sopenharmony_ci 258162306a36Sopenharmony_ci err = devm_request_irq(&pdev->dev, aes_dd->irq, atmel_aes_irq, 258262306a36Sopenharmony_ci IRQF_SHARED, "atmel-aes", aes_dd); 258362306a36Sopenharmony_ci if (err) { 258462306a36Sopenharmony_ci dev_err(dev, "unable to request aes irq.\n"); 258562306a36Sopenharmony_ci goto err_tasklet_kill; 258662306a36Sopenharmony_ci } 258762306a36Sopenharmony_ci 258862306a36Sopenharmony_ci /* Initializing the clock */ 258962306a36Sopenharmony_ci aes_dd->iclk = devm_clk_get(&pdev->dev, "aes_clk"); 259062306a36Sopenharmony_ci if (IS_ERR(aes_dd->iclk)) { 259162306a36Sopenharmony_ci dev_err(dev, "clock initialization failed.\n"); 259262306a36Sopenharmony_ci err = PTR_ERR(aes_dd->iclk); 259362306a36Sopenharmony_ci goto err_tasklet_kill; 259462306a36Sopenharmony_ci } 259562306a36Sopenharmony_ci 259662306a36Sopenharmony_ci err = clk_prepare(aes_dd->iclk); 259762306a36Sopenharmony_ci if (err) 259862306a36Sopenharmony_ci goto err_tasklet_kill; 259962306a36Sopenharmony_ci 260062306a36Sopenharmony_ci err = atmel_aes_hw_version_init(aes_dd); 260162306a36Sopenharmony_ci if (err) 260262306a36Sopenharmony_ci goto err_iclk_unprepare; 260362306a36Sopenharmony_ci 260462306a36Sopenharmony_ci atmel_aes_get_cap(aes_dd); 260562306a36Sopenharmony_ci 260662306a36Sopenharmony_ci#if IS_ENABLED(CONFIG_CRYPTO_DEV_ATMEL_AUTHENC) 260762306a36Sopenharmony_ci if (aes_dd->caps.has_authenc && !atmel_sha_authenc_is_ready()) { 260862306a36Sopenharmony_ci err = -EPROBE_DEFER; 260962306a36Sopenharmony_ci goto err_iclk_unprepare; 261062306a36Sopenharmony_ci } 261162306a36Sopenharmony_ci#endif 261262306a36Sopenharmony_ci 261362306a36Sopenharmony_ci err = atmel_aes_buff_init(aes_dd); 261462306a36Sopenharmony_ci if (err) 261562306a36Sopenharmony_ci goto err_iclk_unprepare; 261662306a36Sopenharmony_ci 261762306a36Sopenharmony_ci err = atmel_aes_dma_init(aes_dd); 261862306a36Sopenharmony_ci if (err) 261962306a36Sopenharmony_ci goto err_buff_cleanup; 262062306a36Sopenharmony_ci 262162306a36Sopenharmony_ci spin_lock(&atmel_aes.lock); 262262306a36Sopenharmony_ci list_add_tail(&aes_dd->list, &atmel_aes.dev_list); 262362306a36Sopenharmony_ci spin_unlock(&atmel_aes.lock); 262462306a36Sopenharmony_ci 262562306a36Sopenharmony_ci err = atmel_aes_register_algs(aes_dd); 262662306a36Sopenharmony_ci if (err) 262762306a36Sopenharmony_ci goto err_algs; 262862306a36Sopenharmony_ci 262962306a36Sopenharmony_ci dev_info(dev, "Atmel AES - Using %s, %s for DMA transfers\n", 263062306a36Sopenharmony_ci dma_chan_name(aes_dd->src.chan), 263162306a36Sopenharmony_ci dma_chan_name(aes_dd->dst.chan)); 263262306a36Sopenharmony_ci 263362306a36Sopenharmony_ci return 0; 263462306a36Sopenharmony_ci 263562306a36Sopenharmony_cierr_algs: 263662306a36Sopenharmony_ci spin_lock(&atmel_aes.lock); 263762306a36Sopenharmony_ci list_del(&aes_dd->list); 263862306a36Sopenharmony_ci spin_unlock(&atmel_aes.lock); 263962306a36Sopenharmony_ci atmel_aes_dma_cleanup(aes_dd); 264062306a36Sopenharmony_cierr_buff_cleanup: 264162306a36Sopenharmony_ci atmel_aes_buff_cleanup(aes_dd); 264262306a36Sopenharmony_cierr_iclk_unprepare: 264362306a36Sopenharmony_ci clk_unprepare(aes_dd->iclk); 264462306a36Sopenharmony_cierr_tasklet_kill: 264562306a36Sopenharmony_ci tasklet_kill(&aes_dd->done_task); 264662306a36Sopenharmony_ci tasklet_kill(&aes_dd->queue_task); 264762306a36Sopenharmony_ci 264862306a36Sopenharmony_ci return err; 264962306a36Sopenharmony_ci} 265062306a36Sopenharmony_ci 265162306a36Sopenharmony_cistatic int atmel_aes_remove(struct platform_device *pdev) 265262306a36Sopenharmony_ci{ 265362306a36Sopenharmony_ci struct atmel_aes_dev *aes_dd; 265462306a36Sopenharmony_ci 265562306a36Sopenharmony_ci aes_dd = platform_get_drvdata(pdev); 265662306a36Sopenharmony_ci 265762306a36Sopenharmony_ci spin_lock(&atmel_aes.lock); 265862306a36Sopenharmony_ci list_del(&aes_dd->list); 265962306a36Sopenharmony_ci spin_unlock(&atmel_aes.lock); 266062306a36Sopenharmony_ci 266162306a36Sopenharmony_ci atmel_aes_unregister_algs(aes_dd); 266262306a36Sopenharmony_ci 266362306a36Sopenharmony_ci tasklet_kill(&aes_dd->done_task); 266462306a36Sopenharmony_ci tasklet_kill(&aes_dd->queue_task); 266562306a36Sopenharmony_ci 266662306a36Sopenharmony_ci atmel_aes_dma_cleanup(aes_dd); 266762306a36Sopenharmony_ci atmel_aes_buff_cleanup(aes_dd); 266862306a36Sopenharmony_ci 266962306a36Sopenharmony_ci clk_unprepare(aes_dd->iclk); 267062306a36Sopenharmony_ci 267162306a36Sopenharmony_ci return 0; 267262306a36Sopenharmony_ci} 267362306a36Sopenharmony_ci 267462306a36Sopenharmony_cistatic struct platform_driver atmel_aes_driver = { 267562306a36Sopenharmony_ci .probe = atmel_aes_probe, 267662306a36Sopenharmony_ci .remove = atmel_aes_remove, 267762306a36Sopenharmony_ci .driver = { 267862306a36Sopenharmony_ci .name = "atmel_aes", 267962306a36Sopenharmony_ci .of_match_table = atmel_aes_dt_ids, 268062306a36Sopenharmony_ci }, 268162306a36Sopenharmony_ci}; 268262306a36Sopenharmony_ci 268362306a36Sopenharmony_cimodule_platform_driver(atmel_aes_driver); 268462306a36Sopenharmony_ci 268562306a36Sopenharmony_ciMODULE_DESCRIPTION("Atmel AES hw acceleration support."); 268662306a36Sopenharmony_ciMODULE_LICENSE("GPL v2"); 268762306a36Sopenharmony_ciMODULE_AUTHOR("Nicolas Royer - Eukréa Electromatique"); 2688